Joomla! MFA Authentication Bypass Vulnerability (CVE-2026-73337) — High Severity

Joomla! MFA Authentication Bypass Vulnerability (CVE-2026-73337) — High Severity

A significant security flaw has been identified in Joomla!, a popular content management system. This vulnerability, tracked as CVE-2026-73337, allows an attacker to bypass the multi-factor authentication (MFA) process. MFA is a crucial security layer designed to protect user accounts even if passwords are stolen, so bypassing it is a serious concern. This means that even with MFA enabled, unauthorized individuals could potentially gain access to user accounts due to insufficient checks in the system’s state management.

CVE Details

  • Product: Joomla!
  • Published Date: August 18, 2026
  • Severity: High
  • Status: Analyzed

Affected Products

The authentication bypass vulnerability affects several versions of the Joomla! CMS. Specifically, users running the following versions are at risk:

  • Joomla! CMS versions 4.0.0 through 5.4.7
  • Joomla! CMS versions 6.0.0 through 6.1.2

It is crucial for administrators and developers using these versions to take immediate action to protect their installations.

Current Status

This vulnerability has been thoroughly analyzed by the Joomla! Security Strike Team. They have confirmed the existence of the MFA authentication bypass and have released patches to address the issue. The vulnerability stems from insufficient state checks, which create an opening for attackers to circumvent the 2FA security measures.

Severity Level

Rated as High severity, CVE-2026-73337 poses a substantial risk. A successful exploit could allow an attacker to bypass multi-factor authentication, potentially leading to unauthorized access to user accounts within the Joomla! CMS. This could compromise sensitive data, allow for website defacement, or enable further malicious activities depending on the privileges of the bypassed account.

Possible Solutions

To mitigate the risk associated with CVE-2026-73337, Joomla! has released updated versions that include the necessary fixes. All users of affected versions are strongly advised to upgrade their Joomla! installations immediately to one of the following patched versions:

  • Upgrade to Joomla! version 5.4.8
  • Upgrade to Joomla! version 6.1.3

Regularly updating your CMS is a fundamental practice in maintaining strong web security. Always back up your website before performing any updates.

References

https://developer.joomla.org/security-centre/1074-20260807-core-mfa-authentication-bypass.html
https://www.joomla.org/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.