Description
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives.
Published: 2026-08-12
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in Joomla! CMS com_joomlaupdate's extraction routine, allowing a Super User to extract a ZIP archive containing directory traversal or absolute path entries. When processed, these entries cause files to be written outside the intended destination, enabling an attacker to drop arbitrary files—including PHP scripts—into web‑accessible locations. If executed, the attacker gains persistent remote code execution and full site compromise.

Affected Systems

Joomla! CMS version 6.1.1 is affected through the com_joomlaupdate component. No other versions are listed as vulnerable. The issue applies to administrators with Super User rights who handle update archives via the update interface.

Risk and Exploitability

The CVSS score of 8.7 denotes a high severity. EPSS is not available, and the vulnerability is not in the CISA KEV catalog, yet the potential for remote code execution remains serious. Exploitation requires inducing a Super User to extract a malicious archive, limiting the attack surface to privileged users, but the impact once successful is full compromise. Immediate patching is strongly recommended.

Generated by OpenCVE AI on August 13, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Joomla! CMS update that includes the com_joomlaupdate path‑traversal fix.
  • Modify or patch the com_joomlaupdate extract.php routine to reject ZIP entries containing '..' or absolute paths, ensuring files are written only within the intended directory.
  • Configure the web server or directory permissions to prevent execution of PHP files in the update extraction location, adding an extra layer of protection if a path‑traversal escape occurs.

Generated by OpenCVE AI on August 13, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Mon, 17 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Joomla is a CNA in scope. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives.
Title Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Joomla is a CNA in scope.
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla joomla\!
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Mon, 17 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla joomla\!
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla joomla\!

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Wed, 12 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.
Title Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: REJECTED

Assigner: VulnCheck

Published:

Updated: 2026-08-17T19:15:06.958Z

Reserved: 2026-08-11T21:47:14.059Z

Link: CVE-2026-73327

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2026-08-12T18:18:15.480

Modified: 2026-08-17T20:16:46.453

Link: CVE-2026-73327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:22Z

Weaknesses

No weakness.