CVE-2026-48897: Joomla! Core - [20260512] - MFA Authentication Bypass
Published May 26, 2026
·Updated
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Affected Software
3 affected components
Joomla Joomla! Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48897?
CVE-2026-48897 has a high severity rating of 8.2 according to CVSS.
2
How do I fix CVE-2026-48897?
To fix CVE-2026-48897, ensure you update your Joomla installation to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-48897?
CVE-2026-48897 is classified as an authentication bypass vulnerability affecting the multi-factor authentication process.
4
What could happen if I don't address CVE-2026-48897?
Failing to address CVE-2026-48897 could allow unauthorized users to bypass two-factor authentication and gain access to accounts.
5
Which software is affected by CVE-2026-48897?
CVE-2026-48897 affects Joomla and Joomla! Core installations.