CVE-2026-76597
Received Received - Intake

Unauthenticated File Upload in Fabrik Joomla Extension

Vulnerability report for CVE-2026-76597, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: Joomla! Project

Description

Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fabrik email_plugin to 4.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated arbitrary file upload vulnerability in the Fabrik Joomla extension. It affects the list email plugin in versions before 4.7.2. Attackers can upload non-executable files directly to the web root without authentication.

Detection Guidance

Check for unauthorized file uploads in the Fabrik list email plugin directory. Inspect web server logs for POST requests to /plugins/fabrik_list/email/email.php with file upload parameters. Look for unexpected files in the web root, especially with extensions not typically allowed.

Impact Analysis

An attacker could upload malicious files to your server, potentially leading to remote code execution, defacement, or further compromise of your Joomla site and hosting environment.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's integrity and confidentiality requirements and HIPAA's security rules for protected health information.

Mitigation Strategies

Update Fabrik to version 4.7.2 or later immediately. Temporarily disable the list email plugin if an update is not immediately possible. Review and restrict file upload permissions in the plugin directory to prevent unauthorized file writes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76597. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart