Description
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
Published: 2026-08-10
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to execute arbitrary code by exploiting the ajax_calc feature of the Fabrik calc plugin, a flaw present in Fabrik versions older than 4.7.2. It arises from improper control over user‑supplied input, enabling arbitrary code execution as described by CWE‑94. An attacker who can trigger this endpoint could gain full control of the affected server’s environment, compromise data confidentiality, integrity, and availability, and potentially pivot to other systems.

Affected Systems

The Fabrik extension for Joomla versions older than 4.7.2 is affected. This includes all installations that rely on the ajax_calc functionality of the Fabrik plugin without a later patch. If an organization uses older versions of the extension, the vulnerability applies regardless of other Joomla component versions.

Risk and Exploitability

The CVSS score of 10 indicates the highest severity, and the EPSS score < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the lack of an authentication requirement and the generic nature of the ajax_calc endpoint make successful exploitation highly feasible in real‑world scenarios. The likely attack vector is web‑based, requiring only an unauthenticated HTTP request to the Fabrik ajax_calc endpoint.

Generated by OpenCVE AI on August 22, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or later. This is the official fix issued by the vendor.
  • Disable or restrict the ajax_calc feature via Joomla’s ACL settings or web‑server configuration to block unauthenticated access.
  • Monitor Joomla logs for suspicious activity targeting the Fabrik component and apply any future security patches from the vendor as they become available.

Generated by OpenCVE AI on August 22, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin. Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
Title Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.7.2

Wed, 12 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin. Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
Title Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.7 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Mon, 10 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 10 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
Title Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.7
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-22T14:20:44.986Z

Reserved: 2026-07-28T12:23:00.876Z

Link: CVE-2026-66915

cve-icon Vulnrichment

Updated: 2026-08-10T10:57:55.468Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T10:17:33.310

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-66915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T15:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')