Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-77995: miniOrange OAuth Client lets attackers take over any Joomla account
CVE-2026-77995 · published 10 days ago
Summary
The miniOrange OAuth Client extension for Joomla (versions before 3.2.0) can be fooled by changing a small piece of data stored in the web browser, allowing someone to log in as any user, even an administrator. This could give an attacker full control of the website and its data. Update the extension to version 3.2.0 or later (or remove it) and check for any unexpected logins.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| miniorange.com | miniorange oauth client extension for joomla | 1.0.0-3.1.9 |
Original advisory text
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
References
- https://www.miniorange.com/ product
Severity
10.0
Critical
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published24 Aug 2026
Updated30 Aug 2026
First seen24 Aug 2026
Monitor software like this
Free during beta