SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76607

CRITICAL · CVSS 10 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Fabrik Joomla extension versions prior to 4.7.3 are vulnerable due to a missing Access Control List (ACL) check in the download element, allowing unauthorized users to access and download sensitive files. This critical vulnerability poses a severe risk of data exposure and exploitation, making it imperative for all Joomla users utilizing the Fabrik extension to prioritize immediate updates to version 4.7.3 or later. Organizations relying on this extension should act swiftly to mitigate potential breaches.

CVE
CVE-2026-76607
Severity
CRITICAL
CVSS
10
EPSS
0.24%

Original NVD Description

Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.