SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60032

CRITICAL · CVSS 9.4 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The JMedia extension for Joomla versions prior to 1.6.0 is susceptible to an authenticated arbitrary file upload vulnerability, allowing attackers to upload executable files and potentially achieve remote code execution. This issue arises from improper handling of file permissions, which fails to strip execute bits from uploaded files. Joomla administrators and users of the JMedia extension should prioritize patching or upgrading to mitigate the risk of exploitation.

CVE
CVE-2026-60032
Severity
CRITICAL
CVSS
9.4
EPSS
0.24%

Original NVD Description

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.