PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73337 Joomla! Project CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T16:18:16.893Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2, allowing for a bypass of 2FA checks due to insufficient state checks. Administrators and users should review system deployments and prioritize patching or mitigations. The CVSS score is 8.2 with HIGH severity. Evidence is limited, and defenders should verify affected deployments and review official advisories.

Vendor
Joomla! Project
Product
Joomla! CMS
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-03
Advisory published
2026-08-18
Advisory updated
2026-09-03

Who should care

Administrators and users of Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2 should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing system deployments, assessing potential impact, and prioritizing patching or mitigations. Security teams and vulnerability management teams should also review and act on this information to ensure proper defenses are in place.

Technical summary

The CVE record describes a vulnerability in Joomla! Core, where insufficient state checks allow for a vector to bypass 2FA checks. This affects Joomla versions 4.0.0-5.4.7 and 6.0.0-6.1.2, with a CVSS score of 8.2 and HIGH severity. The vulnerability allows attackers to bypass 2FA checks, potentially leading to authentication bypass attacks. Organizations should prioritize patching to prevent potential attacks.

Defensive priority

Organizations using Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2 should prioritize patching to prevent potential authentication bypass attacks.

Recommended defensive actions

  • Apply patches or updates to Joomla! Core versions 4.0.0-5.4.7 and 6.0.0-6.1.2
  • Implement additional authentication measures
  • Monitor for suspicious activity

Evidence notes

The CVE record indicates insufficient state checks in Joomla! Core, leading to a vector for bypassing 2FA checks. Affected versions include Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2. Vendor advisory and product information are available. Evidence is limited, and defenders should verify affected deployments and review official advisories for further details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73337 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73337

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73337 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73337

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.