CVE-2026-76603
Received Received - Intake

Unauthenticated Row Disclosure in Fabrik Joomla Extension

Vulnerability report for CVE-2026-76603, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: Joomla! Project

Description

Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.3 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fabrikar fabrik to 4.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Joomla extension Fabrik, specifically versions before 4.7.3. It allows unauthenticated users to view rows of data they should not have access to through the form.inlineedit feature. The issue occurs because the inlineedit form controller does not perform proper access checks.

Detection Guidance

Check if Fabrik versions older than 4.7.3 are installed by inspecting Joomla extensions. Look for unauthorized data access patterns in web server logs, particularly requests to form.inlineedit endpoints without authentication.

Impact Analysis

Unauthenticated attackers could access sensitive data stored in Fabrik forms, potentially exposing confidential information. This could lead to data breaches, unauthorized data exposure, or further exploitation if the disclosed data contains credentials or personal information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by exposing personal or health data to unauthorized parties. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update Fabrik to version 4.7.3 or later immediately. If updating is not possible, disable the Fabrik extension or restrict access to the form.inlineedit controller via server rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76603. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart