CVE-2026-48897

joomla: Improper Authentication (CVE-2026-48897)

Affected

  • bitnami/joomla 4.0.0..*
  • bitnami/joomla 6.0.0..*

Description

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamijoomla
4.0.06.0.0

Metrics

8.2
Source: nvd-v4
28.1 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-05-29 08:44 UTC
CWE-287

Weakness classes (CWE)

  • CWE-287Class

    Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

    cwe.mitre.org →

References & sources