OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92227

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 5.4.8 and 6.0.0 to 6.1.3 are vulnerable to a multi-factor authentication (MFA) bypass due to the premature issuance of "remember me" cookies. This vulnerability allows attackers to circumvent MFA protections, potentially granting unauthorized access to user accounts. Organizations using affected Joomla! versions should prioritize remediation to safeguard against unauthorized access risks.

CVE
CVE-2026-92227
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)