
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-92227 is a Multi-Factor Authentication (MFA) bypass vulnerability in Joomla! CMS caused by the premature issuance of a rememberme cookie. It affects Joomla! CMS versions 4.0.0–5.4.8 and 6.0.0–6.1.3. The vulnerability was published on September 29, 2026, and is classified under security advisory [20260914] by the Joomla! Project. It carries a CVSS v4.0 base score of 8.2 (High) (Joomla Advisory, Feedly).
The root cause is classified as CWE-287 (Improper Authentication): Joomla! CMS issues a rememberme cookie prematurely — before the MFA challenge is completed — allowing an attacker to use that cookie to authenticate as a user without satisfying the second factor. The attack vector is network-based, requires no privileges and no user interaction, but does require specific attack conditions (AT:P in CVSS v4.0 terms, indicating the attacker must be able to obtain or manipulate the prematurely issued cookie). This flaw maps to CAPEC patterns including Authentication Bypass (CAPEC-115), Session Hijacking (CAPEC-593), and Token Impersonation (CAPEC-633) (Joomla Advisory, Feedly).
Successful exploitation allows an unauthenticated attacker to bypass MFA protections and gain unauthorized access to Joomla! user accounts, including potentially privileged administrator accounts. The primary impact is a high integrity risk — an attacker who gains account access could modify site content, install malicious extensions (e.g., web shells via CAPEC-650/T1505.003), or escalate privileges further. Confidentiality and availability are not directly impacted by the bypass itself, but secondary actions post-compromise could affect both (Joomla Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, reflecting low current exploitation probability. The CVE status is "Awaiting Analysis" and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of required privileges make this an attractive target once exploitation techniques become more widely understood.
rememberme cookie issuance.rememberme cookie issued by the server.rememberme cookie in a new authenticated HTTP request, skipping the MFA challenge step entirely, to gain a fully authenticated session.rememberme cookies from unexpected IP addresses or geolocations.components/, plugins/, or templates/ directories following a suspicious login.curl, wget, or shell commands) after a suspicious authentication event.The Joomla! Project recommends updating to a version beyond 5.4.8 (for the 4.x–5.x branch) or beyond 6.1.3 (for the 6.x branch) once patches are released (Joomla Advisory). A community resource notes that Joomla! 5.4.9 and 6.1.4 are the security releases addressing this issue (MySites.guru). As an interim workaround, administrators should consider disabling the rememberme ("Remember Me") login functionality if it is not operationally required, and monitor authentication logs closely for anomalous login patterns. Restricting access to the Joomla! administrator panel via IP allowlisting can also reduce exposure.
The Joomla! Project published an official security advisory (20260914) on September 29, 2026, disclosing the vulnerability and its scope (Joomla Advisory). Community tracking sites such as VulDB and CVEFeed.io indexed the vulnerability shortly after disclosure. No notable independent researcher commentary or significant social media discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."