CVE-2026-67284
Received
Received - Intake
Improper ACL Implementation in Cotton Cloud Plugin
Vulnerability report for CVE-2026-67284, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-12
Last updated on: 2026-08-12
Assigner: Joomla! Project
Description
Description
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| joomla | tabaoca | to 2.0.3 (exc) |
| joomla | cotton_cloud | * |
| joomla | gabble_chat | * |
| joomla | tabapapo_chat | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |