SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76604

CRITICAL · CVSS 10 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Fabrik Joomla extension is vulnerable to unauthenticated remote code execution due to a flaw in its PHP form element, allowing attackers to execute arbitrary code on the server. This critical vulnerability (CVSS 10.0) poses a significant risk to any Joomla installations using affected versions prior to 4.7.3. Organizations utilizing this extension should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76604
Severity
CRITICAL
CVSS
10
EPSS
0.41%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.