[20260807] - Core - MFA Authentication Bypass
Joomla fixed CVE-2026-73337, an MFA authentication bypass caused by insufficient state checks, affecting Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2.
Joomla security advisory 20260807 describes CVE-2026-73337, an authentication bypass in Joomla CMS multi-factor authentication. Insufficient state checks create a vector that allows 2FA checks to be bypassed; the vendor rates the impact as high with moderate probability. Affected versions are 4.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by bloman and Matej Rada on 2026-07-25.
- Insufficient state checks allow bypassing two-factor authentication checks
- Vendor rates impact as high with moderate probability
- Affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2
- Fixed in Joomla 5.4.8 and 6.1.3
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-73337 | MFA/2FA Authentication Bypass in Joomla CMS Core Joomla! core versions 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper-authentication flaw (CWE-287) in which insufficient state checks allow the multi-factor authentication (MFA/2FA) step of login to be bypassed. The CVSS 4.0 vector's attack-requirement metric (AT:P) indicates a present precondition is needed — effectively that MFA is configured on the targeted account or site — while no privileges or user interaction are required. A successful bypass grants the attacker authenticated access without completing the second factor, with the scored impact being high on integrity (CVSS 4.0 score 8.2, High). Any site running Joomla within the affected ranges is affected, which effectively covers all current Joomla 4.x, 5.x and 6.x installs, though only those with MFA in use are exposed to the bypass. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns a 0.3% 30-day exploitation probability, so no exploitation is known as of the 2026-08-07 advisory. Do: Upgrade Joomla core to a release newer than 5.4.7 in the 5.x line or newer than 6.1.2 in the 6.x line, issued with the 2026-08-07 security advisory. Until patched, restrict access to administrator login (e.g., IP allowlisting or VPN) and review admin login logs for sessions that completed without the second factor. Prioritize patching sites and accounts where MFA is enabled, since the bypass is only reachable when multi-factor authentication is configured. | 8.2 | <1% |
| mass≈1 million+ Joomla sites (public CMS market-share and site-scanning data indicate a live Joomla install base above one million, and all supported 4.x–6.x core… |
Project: Joomla! SubProject: CMS Impact: High Severity: Moderate Probability: Moderate Versions: 4.0.0-5.4.7,6.0.0-6.1.2 Exploit type: Authentication Bypass Reported Date: 2026-07-25 Fixed Date: 2026-08-18 CVE Number: CVE-2026-73337 Description Insufficient state checks lead to a vector that allows to bypass 2FA checks. Affected Installs Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: bloman, Matej Rada
This source does not provide full text. Read it at developer.joomla.org.