AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-67282

CRITICAL · CVSS 10 EPSS 0.57% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Fabrikar extension for Joomla versions prior to 4.6.8 is vulnerable to unauthenticated remote code execution, allowing attackers to execute arbitrary code through the frontend listfilter model. This critical vulnerability poses a significant risk to any Joomla installations utilizing the affected extension, making it imperative for administrators to prioritize immediate updates or mitigations. Organizations relying on this extension should take urgent action to safeguard their systems against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67282
Severity
CRITICAL
CVSS
10
EPSS
0.57%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.