CVE-2026-74803
Received Received - Intake

Unauthenticated Arbitrary File Upload in YOOtheme Zoo Extension

Vulnerability report for CVE-2026-74803, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Joomla! Project

Description

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
yootheme zoo to 4.1.64 (exc)
yootheme yootheme_pro to 4.1.64 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated attackers to upload arbitrary files to a Joomla website running the Zoo extension version before 4.1.64. The flaw occurs because the image element accepts files based on the client-supplied Content-Type header, which can be manipulated to bypass restrictions and upload malicious files.

Detection Guidance

This vulnerability allows unauthenticated arbitrary file uploads in Zoo extension versions below 4.1.64. To detect it, check if the Zoo extension version is outdated by inspecting the Joomla admin panel or running SQL queries on the Joomla database to find the installed version. Look for unexpected files in web-accessible directories, particularly those with image extensions but containing executable code.

Impact Analysis

An attacker could exploit this to upload malicious files like web shells, which could lead to full system compromise, data theft, or unauthorized access to the website. Since no authentication is required, any unpatched system is at high risk of exploitation.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face fines, legal liabilities, and reputational damage if exploited.

Mitigation Strategies

Update the Zoo extension to version 4.1.64 or later to address the unauthenticated arbitrary file upload vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74803. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart