Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-77995: miniOrange OAuth Client lets attackers take over any Joomla account

CVE-2026-77995 · published 10 days ago
Summary

The miniOrange OAuth Client extension for Joomla (versions before 3.2.0) can be fooled by changing a small piece of data stored in the web browser, allowing someone to log in as any user, even an administrator. This could give an attacker full control of the website and its data. Update the extension to version 3.2.0 or later (or remove it) and check for any unexpected logins.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
miniorange.com miniorange oauth client extension for joomla 1.0.0-3.1.9
Original advisory text
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
References
Severity
10.0 Critical
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published24 Aug 2026
Updated30 Aug 2026
First seen24 Aug 2026
Sources
CVE-2026-77995 · MITRE
Monitor software like this
Free during beta