AI analysis
Joomla! core versions 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper-authentication flaw (CWE-287) in which insufficient state checks allow the multi-factor authentication (MFA/2FA) step of login to be bypassed. The CVSS 4.0 vector's attack-requirement metric (AT:P) indicates a present precondition is needed — effectively that MFA is configured on the targeted account or site — while no privileges or user interaction are required. A successful bypass grants the attacker authenticated access without completing the second factor, with the scored impact being high on integrity (CVSS 4.0 score 8.2, High). Any site running Joomla within the affected ranges is affected, which effectively covers all current Joomla 4.x, 5.x and 6.x installs, though only those with MFA in use are exposed to the bypass. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns a 0.3% 30-day exploitation probability, so no exploitation is known as of the 2026-08-07 advisory.
What to do: Upgrade Joomla core to a release newer than 5.4.7 in the 5.x line or newer than 6.1.2 in the 6.x line, issued with the 2026-08-07 security advisory. Until patched, restrict access to administrator login (e.g., IP allowlisting or VPN) and review admin login logs for sessions that completed without the second factor. Prioritize patching sites and accounts where MFA is enabled, since the bypass is only reachable when multi-factor authentication is configured.
Affected
| Joomla! CMS (core) | 4.0.0 through 5.4.7 inclusive |
| Joomla! CMS (core) | 6.0.0 through 6.1.2 inclusive |
Estimated exposure
mass≈1 million+ Joomla sites (public CMS market-share and site-scanning data indicate a live Joomla install base above one million, and all supported 4.x–6.x core… — Third-party web-technology surveys and CMS market-share scans consistently place Joomla's live install base at on the order of a million or more sites, and because this is a core flaw spanning all current major versions, essentially the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.