This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Apply the latest Joomla! CMS update that includes the com_joomlaupdate path‑traversal fix.
- Modify or patch the com_joomlaupdate extract.php routine to reject ZIP entries containing '..' or absolute paths, ensuring files are written only within the intended directory.
- Configure the web server or directory permissions to prevent execution of PHP files in the update extraction location, adding an extra layer of protection if a path‑traversal escape occurs.
Generated by OpenCVE AI on August 13, 2026 at 00:15 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Mon, 17 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Joomla is a CNA in scope. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives. |
| Title | Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Mon, 17 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Joomla is a CNA in scope. |
| CPEs | ||
| Vendors & Products |
Joomla joomla\!
|
|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 17 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomla joomla\!
|
|
| CPEs | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joomla joomla\!
|
Thu, 13 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomla
Joomla joomla! |
|
| Vendors & Products |
Joomla
Joomla joomla! |
Wed, 12 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files. | |
| Title | Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T19:15:06.958Z
Reserved: 2026-08-11T21:47:14.059Z
Link: CVE-2026-73327
Updated:
Status : Rejected
Published: 2026-08-12T18:18:15.480
Modified: 2026-08-17T20:16:46.453
Link: CVE-2026-73327
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:39:22Z
No weakness.