AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66491

HIGH · CVSS 8.2 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Phoca Commander extension for Joomla is vulnerable to arbitrary file read due to improper path restrictions in the getSource function, allowing attackers to access sensitive files on the server. This high-severity vulnerability could lead to data exposure and compromise the integrity of the affected systems. Joomla administrators and developers using this extension should prioritize immediate remediation to mitigate potential risks.

CVE
CVE-2026-66491
Severity
HIGH
CVSS
8.2
EPSS
0.31%

Original NVD Description

Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.