Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla MFA bypass affects 4.x and 6.x releases

Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1 to address a Moderate-severity MFA authentication bypass.

The Joomla project has disclosed a security issue in the Core component. The vulnerability is identified as CVE-2026-48896 and is classified as an Authentication Bypass.

A flaw in the handling of authentication state can allow an attacker to get past two-factor authentication checks. The advisory assigns the issue a High impact and Moderate probability, while its overall severity rating is Moderate.

  • Affected versions: Joomla! CMS 4.0.0-5.4.5 and 6.0.0-6.1.0
  • Fixed versions: 5.4.6 and 6.1.1
  • Reported: 2026-04-01
  • Fixed: 2026-05-26

The issue was reported by Doyensec in collaboration with Claude and Anthropic Research, Christos Papakonstantinou, and Cantina. Site owners should apply the matching update promptly, particularly where multi-factor authentication protects administrator accounts.

Published by the Joomla Security Centre.