PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77995 miniorange.com CVE debrief

Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 via cookie value manipulation. This vulnerability allows an attacker to manipulate a cookie value to login as any account, including admin accounts, due to inadequate cookie management and authentication mechanisms. Joomla site administrators and cybersecurity teams should review official advisories and plan for updates or mitigations.

Vendor
miniorange.com
Product
miniOrange OAuth Client (free) extension for Joomla
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-24
Original CVE updated
2026-09-04
Advisory published
2026-08-24
Advisory updated
2026-09-04

Who should care

Joomla site administrators using miniOrange OAuth Client plugin, cybersecurity teams responsible for vulnerability management, developers of Joomla extensions, and operators of affected systems should be aware of this vulnerability and take necessary actions to mitigate it. They should review official advisories, plan for updates or mitigations, and implement additional security measures to prevent exploitation.

Technical summary

The miniOrange OAuth Client plugin for Joomla versions less than 3.2.0 is vulnerable to arbitrary account takeover due to inadequate cookie management and authentication mechanisms. An attacker can manipulate a cookie value to login as any account, including admin accounts. This vulnerability has a critical CVSS score of 10 and requires immediate attention from Joomla site administrators and cybersecurity teams.

Defensive priority

High priority due to critical CVSS score of 10 and potential for admin account takeover.

Recommended defensive actions

  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The evidence from the official CVE Program record and NIST NVD detail page supports an arbitrary account takeover vulnerability in miniOrange OAuth Client < 3.2.0. This vulnerability allows an attacker to manipulate a cookie value to login as any account, including admin accounts, due to inadequate cookie management and authentication mechanisms. Defenders should verify affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations. They should also review compensating controls and check relevant monitoring, detection, and logs for exposed assets.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77995 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77995

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77995 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77995

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.