Joomla! Core Two-Factor Authentication Bypass Vulnerability

Vulnerability

A vulnerability in Joomla! Core has been identified, allowing users to bypass two-factor authentication (2FA) checks. This issue arises from insufficient state checks that incorrectly reset session states, creating a vector for authentication bypass. The vulnerability affects Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling users to bypass two-factor authentication checks.

Remediation

Users are advised to upgrade to Joomla! CMS version 5.4.6 or 6.1.1.

Added: May 26, 2026, 10:59 PM
Updated: May 26, 2026, 10:59 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
5.0
exploitability
6.4
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.