CVE-2026-92227
joomla: Improper Authentication (CVE-2026-92227)
highEPSS 0.3%
Description
Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
bitnamijoomla
4.0.06.0.0Metrics
Show all metrics
Severity
high
73.39
no public PoC known
7.5
8.2
Published
2026-10-07 11:45 UTC
CWE-287
Weakness classes (CWE)
CWE-287Class
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-10-06 16:40 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- CPE Configuration: OR *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 5.4.8 *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.1.3
- Reference Type: Joomla! Project: https://developer.joomla.org/security-centre/1094-20260914-core-mfa-authentication-bypass-through-rememberme-cookies.html Types: Patch, Vendor Advisory
- Reference Type: Joomla! Project: https://www.joomla.org/ Types: Product
- CVE Modified2026-09-30 16:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-92227","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-29 17:17 UTC· security@joomla.org
- Description: Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.
- CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-287
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/92xxx/CVE-2026-92227.json">CVE-2026-92227</a>