{"id":"CVE-2026-73337","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73337","summary":"Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.","details":"Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.","published":"2026-08-18T16:18:16.893","modified":"2026-08-18T16:18:16.893","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://developer.joomla.org/security-centre/20260807-core-mfa-authentication-bypass.html"},{"type":"WEB","url":"https://www.joomla.org/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T16:18:16.893"}}