Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla MFA bypass fixed in 5.4.9 and 6.1.4

Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate-severity MFA authentication bypass involving rememberme cookies.

The Joomla project has disclosed a vulnerability in which a rememberme cookie can be issued prematurely, allowing an attacker to bypass multi-factor authentication. The issue is tracked as CVE-2026-92227.

The advisory rates the impact as High and the probability as Moderate. Its exploit type is listed as Authentication Bypass, making the issue relevant to any site that relies on multi-factor authentication to protect administrator or other authenticated accounts.

  • Affected: Joomla! CMS 4.0.0-5.4.8
  • Affected: Joomla! CMS 6.0.0-6.1.3
  • Fixed: 5.4.9 and 6.1.4

Site owners should update to the applicable fixed release as soon as possible and review their authentication controls after upgrading. The vulnerability was reported by Google and Ada Logics, Mukul Goyal. The Joomla project lists the reported date as 2026-09-10 and the fixed date as 2026-09-25.

Published by the Joomla Security Centre.