SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76598

HIGH · CVSS 8.7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from fabrikar.com is vulnerable to unauthenticated arbitrary directory listing due to the onAjax_getFolders method in versions prior to 4.7.2. This flaw allows attackers to access sensitive directory structures, potentially exposing critical information. Organizations using this extension should prioritize patching to mitigate the risk of data exposure and unauthorized access.

CVE
CVE-2026-76598
Severity
HIGH
CVSS
8.7
EPSS
0.31%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.