Description
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Published: 2026-05-26
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient state checks in Joomla! Core allow an attacker to circumvent the second factor in multi‑factor authentication. By sending a crafted request that bypasses the required state validation, the attacker can gain authenticated access without providing the second factor. This flaw falls under CWE‑287, leading to loss of confidentiality, integrity, and availability for users and administrators who rely on MFA to secure the system. The impact is substantial as the attacker can act with the privileges of a valid user account, potentially modifying site content, accessing sensitive data, or executing administrative commands.

Affected Systems

All installations of Joomla! CMS that have MFA enabled are potentially vulnerable. The CNA record does not list specific patch versions, so administrators should verify whether the installed version contains the fix once it becomes available. In short, any self‑hosted or hosted site running a Joomla! version before the official patch is at risk.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests a very low but non‑zero exploitation probability at the time of analysis. The vulnerability is not listed in CISA's KEV catalog, but its high impact remains unchanged. Based on the description, the likely attack vector is an application‑layer web request that manipulates session state or submits crafted data to bypass MFA checks. No public exploits have been reported yet, so the risk is moderate until the vulnerability becomes more widely known.

Generated by OpenCVE AI on May 28, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Joomla! CMS to the latest version that contains the patch for the MFA bypass.
  • Verify that MFA state validation is enforced and remove any fallback paths that skip MFA checks.
  • Monitor authentication logs for successful logins that do not include a second factor and configure alerts for suspicious login activity.

Generated by OpenCVE AI on May 28, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomla joomla!
Vendors & Products Joomla joomla!

Thu, 28 May 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla\!
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla
Joomla joomla\!
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Tue, 26 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Title Joomla! Core - [20260511] - MFA Authentication Bypass
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-05-27T09:15:12.329Z

Reserved: 2026-05-26T10:06:17.656Z

Link: CVE-2026-48896

cve-icon Vulnrichment

Updated: 2026-05-26T18:56:23.235Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-26T17:16:54.213

Modified: 2026-05-28T19:46:20.930

Link: CVE-2026-48896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:51:23Z

Weaknesses