ZeroHour

CVE-2026-73337

mass

MFA/2FA Authentication Bypass in Joomla CMS Core

CVSS 4.0
8.2 high
EPSS
<1%p19
Published
()
Modified
AI analysis

Joomla! core versions 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper-authentication flaw (CWE-287) in which insufficient state checks allow the multi-factor authentication (MFA/2FA) step of login to be bypassed. The CVSS 4.0 vector's attack-requirement metric (AT:P) indicates a present precondition is needed — effectively that MFA is configured on the targeted account or site — while no privileges or user interaction are required. A successful bypass grants the attacker authenticated access without completing the second factor, with the scored impact being high on integrity (CVSS 4.0 score 8.2, High). Any site running Joomla within the affected ranges is affected, which effectively covers all current Joomla 4.x, 5.x and 6.x installs, though only those with MFA in use are exposed to the bypass. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns a 0.3% 30-day exploitation probability, so no exploitation is known as of the 2026-08-07 advisory.

What to do: Upgrade Joomla core to a release newer than 5.4.7 in the 5.x line or newer than 6.1.2 in the 6.x line, issued with the 2026-08-07 security advisory. Until patched, restrict access to administrator login (e.g., IP allowlisting or VPN) and review admin login logs for sessions that completed without the second factor. Prioritize patching sites and accounts where MFA is enabled, since the bypass is only reachable when multi-factor authentication is configured.

Affected
Joomla! CMS (core)4.0.0 through 5.4.7 inclusive
Joomla! CMS (core)6.0.0 through 6.1.2 inclusive
Estimated exposure
mass≈1 million+ Joomla sites (public CMS market-share and site-scanning data indicate a live Joomla install base above one million, and all supported 4.x–6.x core… — Third-party web-technology surveys and CMS market-share scans consistently place Joomla's live install base at on the order of a million or more sites, and because this is a core flaw spanning all current major versions, essentially the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-287
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

[20260807] - Core - MFA Authentication Bypass

Joomla fixed CVE-2026-73337, an MFA authentication bypass caused by insufficient state checks, affecting Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260807 describes CVE-2026-73337, an authentication bypass in Joomla CMS multi-factor authentication. Insufficient state checks create a vector that allows 2FA checks to be bypassed; the vendor rates the impact as high with moderate probability. Affected versions are 4.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by bloman and Matej Rada on 2026-07-25.

Joomla Security Centre · 29d agoAdvisoryCVE-2026-73337