CyberRota Analysis
AI-GeneratedThe Fabrik extension for Joomla versions prior to 4.7.2 is vulnerable to unauthenticated access, allowing attackers to list arbitrary database tables and their columns through the ajax_tables method. This exposure could lead to sensitive data disclosure and potential exploitation of the underlying database. Joomla administrators and developers using this extension should prioritize applying the latest update to mitigate the risk.
CVE
CVE-2026-76599
Severity
HIGH
CVSS
8.7
EPSS
0.29%
Original NVD Description
Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.