Security
Joomla MFA bypass fixed in security updates
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1, respectively, to fix an MFA authentication bypass.
The Joomla project has published details of a security issue in the CMS authentication flow. Tracked as CVE-2026-48897, the vulnerability involves session states being reset incorrectly. Under the affected conditions, that state could allow an attacker to get past two-factor authentication checks.
The project classifies the exploit type as Authentication Bypass. Its assigned impact is High, while both the severity and probability ratings are Moderate. The issue concerns the core Joomla! CMS, rather than an independently installed extension.
Joomla administrators should review their deployed branches and apply the corresponding maintenance release. Sites that cannot be updated immediately should treat the advisory as a priority because multi-factor authentication may not provide its intended protection when the vulnerable session handling is triggered.
The issue was reported by Morris Baumgarten-Egemole. The Joomla Security Centre lists 2026-04-01 as the reported date and 2026-05-26 as the fixed date.
Published by the Joomla Security Centre.