All findings

CVE-2026-40383, CVE-2026-40384, CVE-2026-48896 high

Joomla credits Doyensec and Claude on three May 2026 CMS CVEs

Joomla's May 26, 2026 security advisories credit Doyensec in collaboration with Claude and Anthropic Research for local file inclusion, path traversal, and MFA bypass vulnerabilities.

Bug class
Local file inclusion, path traversal, and authentication bypass
Affected codebase
Joomla CMS
Credited system
Claude / Anthropic Research
Disclosed
May 26, 2026
Attribution
Direct source attribution
Severity
high
Source status: Joomla's security center directly credits Doyensec in collaboration with Claude and Anthropic Research on all three advisories. CVE-2026-48896 is shared with additional reporters; the Claude-assisted credit remains explicit.

Summary

Joomla’s May 26, 2026 release wave included three CMS vulnerabilities with explicit Claude collaboration credits:

Attribution

This is direct upstream attribution. The Joomla Security Centre identifies the project, affected versions, exploit type, fixed versions, CVE number, and reporter credit for each issue.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.