SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-73337

HIGH · CVSS 7.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Joomla versions 4.0.0 to 5.4.7 and 6.0.0 to 6.1.2 are vulnerable to a multi-factor authentication (MFA) bypass due to insufficient state checks, allowing attackers to circumvent two-factor authentication protections. This vulnerability poses a significant risk as it can enable unauthorized access to user accounts, potentially compromising sensitive data. Organizations using affected Joomla versions should prioritize immediate patching to mitigate the risk of exploitation.

CVE
CVE-2026-73337
Severity
HIGH
CVSS
7.5
EPSS
0.27%

Original NVD Description

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)