SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76597

HIGH · CVSS 8.7 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from fabrikar.com is vulnerable to unauthenticated arbitrary file uploads through the list email plugin in versions prior to 4.7.2, allowing attackers to upload non-executable files to the web root. This could lead to potential exploitation, including data exposure or further attacks on the web application. Joomla administrators and users of the Fabrik extension should prioritize patching to mitigate this high-severity vulnerability.

CVE
CVE-2026-76597
Severity
HIGH
CVSS
8.7
EPSS
0.35%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.