Security
miniOrange OAuth Client flaw enables Joomla account takeover
A critical flaw in the miniOrange OAuth Client extension for Joomla allows unauthenticated account takeover, including access to administrator accounts.
Research published by mySites.guru says the extension trusts a cookie value supplied by the visitor when identifying the logged-in account. Changing that value can therefore grant access to another user without credentials or prior access.
The vulnerability is tracked as CVE-2026-77995 and classified as CWE-287, improper authentication. The Joomla CNA rates it CVSS 10.0, Critical. The report does not identify active exploitation in the wild.
- Affected:
miniOrange OAuth Clientversions1.0.0through3.1.9 - Fixed:
3.2.0and later - Vendor: miniOrange
Administrators should update the extension on every affected Joomla site. If an immediate update is not possible, disable or remove it until a fixed release can be installed. Sites that previously ran a vulnerable version should also be checked for unfamiliar administrator or Super User accounts and suspicious activity in Joomla and server logs.
Originally reported by mySites.guru.