PatchSiren cyber security CVE debrief
CVE-2026-73337 Joomla! Project CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T16:18:16.893Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2, allowing for a bypass of 2FA checks due to insufficient state checks. Administrators and users should review system deployments and prioritize patching or mitigations. The CVSS score is 8.2 with HIGH severity. Evidence is limited, and defenders should verify affected deployments and review official advisories.
- Vendor
- Joomla! Project
- Product
- Joomla! CMS
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-03
Who should care
Administrators and users of Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2 should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing system deployments, assessing potential impact, and prioritizing patching or mitigations. Security teams and vulnerability management teams should also review and act on this information to ensure proper defenses are in place.
Technical summary
The CVE record describes a vulnerability in Joomla! Core, where insufficient state checks allow for a vector to bypass 2FA checks. This affects Joomla versions 4.0.0-5.4.7 and 6.0.0-6.1.2, with a CVSS score of 8.2 and HIGH severity. The vulnerability allows attackers to bypass 2FA checks, potentially leading to authentication bypass attacks. Organizations should prioritize patching to prevent potential attacks.
Defensive priority
Organizations using Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2 should prioritize patching to prevent potential authentication bypass attacks.
Recommended defensive actions
- Apply patches or updates to Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2
- Implement additional authentication measures
- Monitor for suspicious activity
Evidence notes
The CVE record indicates insufficient state checks in Joomla! Core, leading to a vector for bypassing 2FA checks. Affected versions include Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2. Vendor advisory and product information are available. Evidence is limited, and defenders should verify affected deployments and review official advisories for further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73337 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73337
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73337 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73337
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://developer.joomla.org/security-centre/1074-20260807-core-mfa-authentication-bypass.html
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.joomla.org/
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.