Joomla · Joomla! · CVE-2026-73337
**Name of the Vulnerable Software and Affected Versions**
Joomla! Core versions 4.0.0 through 5.4.7
Joomla! Core versions 6.0.0 through 6.1.2
**Description**
Insufficient state checks create a vector that allows an attacker to bypass Multi-Factor Authentication (MFA) checks, which are used to verify a user's identity through two-factor authentication (2FA).
**Recommendations**
Update Joomla! Core versions 4.0.0 through 5.4.7 to a version newer than 5.4.7.
Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.