CVE-2026-92227

joomla: Improper Authentication (CVE-2026-92227)

Description

Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamijoomla
4.0.06.0.0

Metrics

8.2
Source: cna-v4
17.3 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-07 11:45 UTC
CWE-287

Weakness classes (CWE)

  • CWE-287Class

    Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-10-06 16:40 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
    • CPE Configuration: OR *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 5.4.8 *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.1.3
    • Reference Type: Joomla! Project: https://developer.joomla.org/security-centre/1094-20260914-core-mfa-authentication-bypass-through-rememberme-cookies.html Types: Patch, Vendor Advisory
    • Reference Type: Joomla! Project: https://www.joomla.org/ Types: Product
  2. CVE Modified2026-09-30 16:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-92227","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-29 17:17 UTC· security@joomla.org
    • Description: Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.
    • CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-287
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/92xxx/CVE-2026-92227.json">CVE-2026-92227</a>