Search Results :

×

miniOrange OAuth Client for Joomla: Security Vulnerability Fix (CVE-2026-77995)

Status: Resolved

1. Summary

• CVE ID = CVE-2026-77995

• Vulnerability Type = Authorization Bypass Through User-Controlled Key (CWE-639)

• Affected Versions = All versions before fixed releases (Only Free versions affected)

• Fixed Version = See Affected Software list below

2. Overview

A critical vulnerability was found in the miniOrange OAuth Client extension for Joomla that allows an unauthenticated attacker to log in as any user on an affected site, including administrator accounts, without valid credentials. Fixed versions are available for every affected product listed below, and sites running an older version should update immediately.

3. Technical Details

Root cause: During the OAuth login flow, the extension decided which account to sign a visitor into based on a cookie value sent from the browser, rather than checking that value against a secure, server-side session. Since a visitor can freely edit their own cookies, this let an attacker set that value to any account they wanted to access.

Attack vector: The vulnerability can be exploited remotely over the network. It requires no valid credentials and no interaction from the targeted user or administrator; an attacker only needs the site URL and a valid user identifier (such as a user ID or email) to set in the cookie, then send a request with that modified cookie value to the site's OAuth login endpoint.

Impact: Exploiting this issue gave an attacker full control of the targeted account, including administrator accounts, which could lead to complete compromise of the site's data and configuration.

4. Affected Software

Free editions of the following miniOrange Joomla extensions:

Joomla Extension Affected Version Fixed Version
miniOrange OAuth Client 1.0.0 - 3.1.9 3.2.0 and later
OAuth Single Sign-On – OIDC SSO | Login with Azure AD 1.0.0 - 1.2.1 1.2.2 and later
Login with Keycloak OAuth Single Sign-On (SSO) 1.0.0 - 1.2.1 1.2.2 and later
Single Sign-On for Educational Institutes 1.0.0 - 1.2.1 1.2.2 and later

5. Vulnerability Resolution

In the fixed versions and later, the extension no longer uses the browser cookie alone to decide which account to log in to. It validates the OAuth session on the server side, so a tampered cookie cannot be used to impersonate another user.

6. Remediation Steps

1. Download the latest version of the extension.

2. Update the miniOrange OAuth extension for Joomla to the fixed version or later.

3. After updating, confirm the extension is running the fixed version or later.

Hello there!

Need Help? We are right here!

support