CVE-2026-77995General

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-25); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-25: 2Mentions · 2026-08-30: 1PoC Mentioned / Linked · 2026-08-25: 1Exploit Tool / Code · 2026-08-25: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-30: 108-2508-30
Signal classification3 categories
General
133.3%
PoC
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-252
General1PoC1
2026-08-301
Patch1
Full discourse3 posts
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-77995 [HIGH PRIORITY] #Joomla Extension - https://miniorange.com - Arbitrary account takeover in miniOrange ... 🔗 https://exploitgrid.net/cve/CVE-2026-77995

    Post summary

    CVE‑2026‑77995 is linked to a Joomla MiniOrange extension, with a direct link to ExploitGrid suggesting a proof‑of‑concept for arbitrary account takeover; no patch or active exploitation discussion is present.

    1000146
    38 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-76070 - EXPLOIT CVE-2026-76071 - EXPLOIT CVE-2025-36939 CVE-2026-77995 CVE-2026-32559 ..🧵👇

    Post summary

    The post is a brief daily digest listing several CVEs, marking two as exploits, but provides no additional technical or exploit details.

    1001070
    38 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🍪 Cookie manipulation = instant admin takeover. miniOrange OAuth Client for Joomla (&lt; 3.2.0) lets attackers hijack any account by forging a cookie value. CVE-2026-77995, CVSS 10. Patch to 3.2.0 now. #cybersecurity #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-77995?utm_campaign=x https://t.co/iPsjV8LO4u

    Post summary

    The tweet announces CVE-2026-77995 affecting miniOrange OAuth Client for Joomla, describing an admin takeover via forged cookies, and confirms a patch is available in version 3.2.0.

    00000108
    884 followersView on X

Explore more