Description
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
Published: 2026-08-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover
Action: Patch ASAP
AI Analysis

Impact

The vulnerability in the miniOrange OAuth Client extension for Joomla enables an attacker to modify a cookie value to authenticate as any user account, including administrators. This flaw permits arbitrary account takeover by bypassing the normal authentication checks, giving the attacker the privileges of the account they impersonate.

Affected Systems

Affected vendors and products include the miniOrange.com extensions: miniOrange OAuth Client for Joomla (vulnerable versions less than 3.2.0), OAuth Single Sign-On – OIDC SSO for Joomla (vulnerable versions less than 1.2.2), Login with Keycloak OAuth Single Sign-On (SSO) for Joomla (vulnerable versions less than 1.2.2), and Single Sign-On for Educational Institutes for Joomla (vulnerable versions less than 1.2.2). Users running Joomla with any of these unpatched extensions must consider the risk.

Risk and Exploitability

The vulnerability has a CVSS score of 10, indicating a critical level of risk. The EPSS score is less than 1%, reflecting a very low but nonzero exploitation probability, and the issue is not listed in the CISA KEV catalog at present. Attackers can exploit the flaw remotely by forging an HTTP cookie in a browser or via an HTTP request, with no additional prerequisites beyond the ability to send a crafted cookie. Because the flaw lies in cookie handling that bypasses authentication, a mitigation strategy centered on updating the extension is strongly recommended.

Generated by OpenCVE AI on September 8, 2026 at 12:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected miniOrange extensions to their latest released versions (miniOrange OAuth Client ≥3.2.0, OAuth Single Sign-On – OIDC SSO ≥1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) ≥1.2.2, Single Sign-On for Educational Institutes ≥1.2.2).
  • If an immediate update is not possible, disable or uninstall the vulnerable extensions from the Joomla installation.
  • Enforce secure cookie attributes (HttpOnly, Secure, SameSite) on the Joomla site to reduce the risk of cookie tampering.

Generated by OpenCVE AI on September 8, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 08 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins. Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
Title Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange.com
Miniorange.com miniorange Oauth Client Extension For Joomla
Vendors & Products Miniorange.com
Miniorange.com miniorange Oauth Client Extension For Joomla

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
Title Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Miniorange.com Miniorange Oauth Client Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-08T10:32:27.629Z

Reserved: 2026-08-21T19:23:55.924Z

Link: CVE-2026-77995

cve-icon Vulnrichment

Updated: 2026-08-24T17:25:57.066Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T14:17:03.403

Modified: 2026-09-08T11:17:44.423

Link: CVE-2026-77995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T12:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key