CVE-2026-73337

Summary

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Affected Software

VendorProductVersion RangeStatus
Joomla! ProjectJoomla! CMS4.0.0-5.4.6affected
Joomla! ProjectJoomla! CMS6.0.0-6.1.2affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References