Security
Joomla MFA bypass affects 4.x and 6.x releases
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1 to address a Moderate-severity MFA authentication bypass.
The Joomla project has disclosed a security issue in the Core component. The vulnerability is identified as CVE-2026-48896 and is classified as an Authentication Bypass.
A flaw in the handling of authentication state can allow an attacker to get past two-factor authentication checks. The advisory assigns the issue a High impact and Moderate probability, while its overall severity rating is Moderate.
- Affected versions: Joomla! CMS
4.0.0-5.4.5and6.0.0-6.1.0 - Fixed versions:
5.4.6and6.1.1 - Reported: 2026-04-01
- Fixed: 2026-05-26
The issue was reported by Doyensec in collaboration with Claude and Anthropic Research, Christos Papakonstantinou, and Cantina. Site owners should apply the matching update promptly, particularly where multi-factor authentication protects administrator accounts.
Published by the Joomla Security Centre.