Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

miniOrange OAuth Client flaw enables Joomla account takeover

A critical flaw in the miniOrange OAuth Client extension for Joomla allows unauthenticated account takeover, including access to administrator accounts.

Research published by mySites.guru says the extension trusts a cookie value supplied by the visitor when identifying the logged-in account. Changing that value can therefore grant access to another user without credentials or prior access.

The vulnerability is tracked as CVE-2026-77995 and classified as CWE-287, improper authentication. The Joomla CNA rates it CVSS 10.0, Critical. The report does not identify active exploitation in the wild.

  • Affected: miniOrange OAuth Client versions 1.0.0 through 3.1.9
  • Fixed: 3.2.0 and later
  • Vendor: miniOrange

Administrators should update the extension on every affected Joomla site. If an immediate update is not possible, disable or remove it until a fixed release can be installed. Sites that previously ran a vulnerable version should also be checked for unfamiliar administrator or Super User accounts and suspicious activity in Joomla and server logs.

Originally reported by mySites.guru.