AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-67283

MEDIUM · CVSS 6.9 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Joomla extension from tabaoca.org is vulnerable due to improper Access Control List (ACL) implementation, allowing unauthenticated users to perform unauthorized file operations, including reading, deleting, and overwriting files. This vulnerability poses a significant risk to the integrity and confidentiality of files managed within the Cotton Cloud version prior to 2.0.2. Organizations using this extension should prioritize remediation to prevent potential exploitation and data loss.

CVE
CVE-2026-67283
Severity
MEDIUM
CVSS
6.9
EPSS
0.25%

Original NVD Description

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.