High severity7.5NVD Advisory· Published Aug 18, 2026· Updated Sep 3, 2026
CVE-2026-73337
CVE-2026-73337
Description
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- developer.joomla.org/security-centre/1074-20260807-core-mfa-authentication-bypass.htmlnvdVendor Advisory
- www.joomla.orgnvdProduct
News mentions
1- Joomla: 17 Vulnerabilities Disclosed, Including Critical Code & SQL Injection FlawsVypr Intelligence · Aug 19, 2026