Description
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.
Published: 2026-08-12
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can trigger arbitrary code execution through the Fabrik front‑end listfilter model in Joomla. The flaw allows the execution of injected code with the privileges of the web server, constituting a full remote code execution vulnerability classified under CWE‑94. The high CVSS score of 10 reflects the potential for complete compromise of the affected host.

Affected Systems

The vulnerability exists in the Fabrik Joomla extension released by fabrikar.com, affecting all installations with a version earlier than 4.6.8. No other products or versions are noted as impacted.

Risk and Exploitability

With no user authentication required, the exploitation path is straightforward: an attacker sends a crafted request to a publicly reachable listfilter endpoint. The EPSS metric is not available, but the CVSS score of 10 indicates a critical attack surface. It is not listed in the CISA KEV catalog currently, yet organizations using an old Fabrik version face an imminent threat from any actor capable of sending HTTP requests to the site.

Generated by OpenCVE AI on August 12, 2026 at 11:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Fabrik update to version 4.6.8 or later, which contains the necessary fix for the command injection flaw.
  • If you are unable to update immediately, disable or uninstall the Fabrik extension until a patch is applied. This will prevent any unauthenticated remote code execution attempts through the listfilter model.
  • Consider restricting access to the Fabrik components by implementing IP whitelisting or firewall rules to limit exposure until a permanent fix is available.

Generated by OpenCVE AI on August 12, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Wed, 12 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.
Title Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:58:16.562Z

Reserved: 2026-07-29T12:12:55.984Z

Link: CVE-2026-67282

cve-icon Vulnrichment

Updated: 2026-08-12T12:31:25.447Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T09:17:30.590

Modified: 2026-08-26T16:36:16.990

Link: CVE-2026-67282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:45:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')