CVE-2026-48896: Joomla! Core - [20260511] - MFA Authentication Bypass
Published May 26, 2026
·Updated
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48896?
CVE-2026-48896 has a severity rating of 8.2, categorized as high.
2
What is CVE-2026-48896 about?
CVE-2026-48896 refers to a vulnerability in Joomla! Core that allows an attacker to bypass multi-factor authentication due to insufficient state checks.
3
How do I fix CVE-2026-48896?
To fix CVE-2026-48896, update to the latest version of Joomla that addresses the multi-factor authentication bypass vulnerability.
4
Who is affected by CVE-2026-48896?
CVE-2026-48896 affects all users and installations of Joomla! Core that implement multi-factor authentication.
5
What actions should I take in response to CVE-2026-48896?
In response to CVE-2026-48896, immediately apply security updates and review authentication practices to enhance security.