AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-67284

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Joomla Extension from tabaoca.org has an improper ACL implementation that permits authenticated users to perform unauthorized file operations, such as reading, deleting, and overwriting files owned by others, in versions prior to 2.0.3. This vulnerability poses a medium risk as it could lead to data exposure and unauthorized modifications within the application. Organizations using this extension should prioritize patching to mitigate potential security breaches.

CVE
CVE-2026-67284
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users.