SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76596

HIGH · CVSS 8.7 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla extension from fabrikar.com is vulnerable to unauthenticated table truncation due to insufficient access control in the list.doempty endpoint, allowing an attacker to execute a simple GET request to empty the target list's table. This vulnerability poses a high risk as it can lead to data loss and disruption of services for affected Joomla installations. Organizations using Fabrik versions prior to 4.7.2 should prioritize immediate updates to mitigate this risk.

CVE
CVE-2026-76596
Severity
HIGH
CVSS
8.7
EPSS
0.24%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table