CVE-2026-48896
joomla: Improper Authentication (CVE-2026-48896)
highEPSS 0.4%
Affected
- bitnami/joomla
4.0.0..* - bitnami/joomla
6.0.0..*
Description
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
bitnamijoomla
4.0.06.0.0Metrics
Show all metrics
Severity
high
66.40
no public PoC known
7.5
8.2
Published
2026-05-29 08:44 UTC
CWE-287
Weakness classes (CWE)
CWE-287Class
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
cwe.mitre.org →