CyberRota Analysis
AI-GeneratedAn unauthenticated arbitrary file upload vulnerability exists in the Zoo extension for Joomla versions prior to 4.1.64, allowing attackers to upload malicious files by manipulating the Content-Type header. This critical flaw could lead to remote code execution and complete system compromise. Organizations using affected versions of the Zoo extension should prioritize immediate patching to mitigate potential exploitation.
CVE
CVE-2026-74803
Severity
CRITICAL
CVSS
10
EPSS
0.31%
Original NVD Description
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.