Source status: Joomla's security center directly credits Doyensec in collaboration with Claude and Anthropic Research on all three advisories. CVE-2026-48896 is shared with additional reporters; the Claude-assisted credit remains explicit.
Summary
Joomla’s May 26, 2026 release wave included three CMS vulnerabilities with explicit Claude collaboration credits:
- CVE-2026-40383, local file inclusion through the HTMLView layout parameter.
- CVE-2026-40384, path traversal in the
com_mediawebservice endpoint. - CVE-2026-48896, an MFA authentication bypass caused by insufficient state checks.
Attribution
This is direct upstream attribution. The Joomla Security Centre identifies the project, affected versions, exploit type, fixed versions, CVE number, and reporter credit for each issue.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.