Description
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
Published: 2026-08-10
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to execute arbitrary code by exploiting the ajax_calc feature of the Fabrik calc plugin. The flaw arises from improper control over user‑supplied input, enabling arbitrary code execution as described by CWE-94. An attacker who can trigger this endpoint could gain full control of the affected server’s environment, compromise data confidentiality, integrity, and availability, and potentially pivot to other systems.

Affected Systems

The Fabrik extension for Joomla versions earlier than 4.6.7 is affected. This includes all installations that rely on the ajax_calc functionality of the Fabrik plugin without a later patch. If an organization uses older versions of the extension, the vulnerability applies regardless of other Joomla component versions.

Risk and Exploitability

The CVSS score of 10 indicates the highest severity, and no exploit probability data is available. The vulnerability is not listed in the CISA KEV catalog, but the lack of an authentication requirement and the generic nature of the ajax_calc endpoint make successful exploitation highly feasible in real‑world scenarios. The likely attack vector is web‑based, requiring only an unauthenticated HTTP request to the Fabrik ajax_calc endpoint.

Generated by OpenCVE AI on August 10, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.6.7 or later. This is the official fix issued by the vendor.
  • Disable or restrict the ajax_calc feature via Joomla’s ACL settings or web‑server configuration to block unauthenticated access.
  • Monitor Joomla logs for suspicious activity targeting the Fabrik component and apply any future security patches from the vendor as they become available.

Generated by OpenCVE AI on August 10, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon
History

Mon, 10 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
Title Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.7
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-10T12:43:25.093Z

Reserved: 2026-07-28T12:23:00.876Z

Link: CVE-2026-66915

cve-icon Vulnrichment

Updated: 2026-08-10T10:57:55.468Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T12:00:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')