Security
Joomla passkey flaw enables user enumeration
Administrators running Joomla! CMS 4.0.0-4.4.13 or 5.0.0-5.3.3 should upgrade to 4.4.14 or 5.3.4 to address a User Enumeration issue in the passkey authentication method, tracked as CVE-2025-54477.
The Joomla project classifies this as Severity: Low, with Impact: Moderate and Probability: Low. The exploit type is User Enumeration. The weakness can allow an attacker to distinguish valid users by observing how the passkey authentication flow handles authentication requests.
This concerns the core passkey authentication method, rather than an extension-specific feature. Site operators should apply the appropriate update for their current Joomla branch and ensure that routine update and access-control procedures cover passkey-enabled accounts.
- 4.x installations should move to
4.4.14. - 5.x installations should move to
5.3.4.
Marco Schubert reported the issue on 2025-09-04. The Joomla project marked it fixed on 2025-09-30. Administrators who cannot update immediately should review passkey usage and monitor authentication activity, while treating the upgrade as the definitive remediation.
Published by the Joomla Security Centre.