Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-77995CriticalPublished 24 August 2026

miniOrange OAuth Client (com_miniorange_oauth) 1.0.0 to 3.1.9 - Unauthenticated Account Takeover

miniOrange OAuth Client versions 1.0.0 to 3.1.9 are affected by an unauthenticated account takeover, CVE-2026-77995, scored CVSS 4.0 10.0 (critical). Manipulation of a cookie value allows an attacker with no login to authenticate as an arbitrary account, Super Users included. Update the miniOrange OAuth Client to 3.2.0 or later. IMPORTANT edition caveat: miniOrange ships several separately numbered OIDC editions under this same com_miniorange_oauth element, including Login with Azure AD, Login with Keycloak OAuth Single Sign-On and Single Sign-On for Educational Institutes. miniOrange confirmed in writing on 26 August 2026 that those three are fixed in 1.2.2, not 3.2.0, and that all of the fixed versions they gave apply to the free editions only. Check the display name of the installed extension before acting on a version number, and if the site reports a two-segment version such as 32.0.1 or 34.0.0 it is a paid edition. miniOrange stated in writing on 4 September 2026 that CVE-2026-77995 was associated only with the free OAuth Client and that their investigation found the flaw in no version of the paid OAuth editions, which is why no paid security build was ever released. This rule's ceiling of 3.1.9 therefore excludes every paid build on purpose, and no paid install has ever been flagged by it. Note that this rests on the vendor's assessment: the CVE record still names a single product with no edition qualifier, and the same vendor scoped the SAML record to the free line before it had to be widened to name all four paid editions.

Affected versions: ≥ 1.0.0 and ≤ 3.1.9

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 14 September 2026.