CVE-2026-102427
Awaiting Analysis Awaiting Analysis - Queue

Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK

Vulnerability report for CVE-2026-102427, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Joomla! Project

Description

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ordasoft joomla_cck to 8.3.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated remote code execution vulnerability in the OrdaSoft Joomla CCK extension versions before 8.3.16. The flaw exists in the uploader.php file, which is accessible through the component's frontend routing without authentication checks. The extension performs a MIME type check on uploaded files but has a commented-out extension allow-list. Attackers can bypass this by uploading an image/PHP polyglot file with a .php extension, which passes the MIME check but executes PHP code when saved to the web root.

Detection Guidance

Check for unauthorized PHP files in your Joomla web root directory, particularly files with .php extensions that may have been uploaded through the vulnerable component. Look for files named uploader.php or any recently modified PHP files in the site root or component directories.

Impact Analysis

This vulnerability allows attackers to execute arbitrary PHP code on your server without authentication. They could take full control of your Joomla site, steal sensitive data, deface the website, or use it as a launch point for further attacks. Since no authentication is required, any visitor to the site could exploit it.

Compliance Impact

This vulnerability could lead to a data breach, exposing personal or sensitive data stored on the Joomla site. Such a breach would likely violate GDPR if EU user data is compromised or HIPAA if protected health information is exposed. Organizations may face regulatory fines, legal liabilities, and reputational damage.

Mitigation Strategies

Update the OrdaSoft Joomla CCK component to version 8.3.16 or later immediately. Remove write permissions from the web root directory to prevent unauthorized file uploads. Review server logs for suspicious activity related to the uploader.php endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102427. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart