Description
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
Published: 2026-08-22
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fabrik extension for Joomla contains an unauthenticated endpoint, list.doempty, that lacks any access‑control checks. An attacker can issue a plain HTTP GET request to this endpoint, which triggers the emptying of the target list’s database table. The result is irreversible data loss for the affected list and potential interruption of services that rely on that data. This flaw is a classic Broken Access Control vulnerability (CWE‑284).

Affected Systems

Any site running the Fabrik extension for Joomla with a version prior to 4.7.2 is affected. No specific sub‑versions were enumerated, but all releases below 4.7.2 should be considered vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The attacker’s path requires only unauthenticated HTTP access to the targeted site, making exploitation trivial for anyone with network visibility to the Joomla installation. Once triggered, the data is permanently lost, and no user‑level authentication is needed to perform the attack.

Generated by OpenCVE AI on August 22, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or later, which removes the unauthenticated list.doempty endpoint.
  • If an upgrade cannot be performed immediately, reconfigure Joomla ACL settings to require authentication for list.doempty or remove the functionality through custom code.
  • Block unauthenticated GET requests to list.doempty using a web server rule or firewall to prevent the truncation until a patch or configuration change is applied.

Generated by OpenCVE AI on August 22, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
Title Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-22T14:20:22.438Z

Reserved: 2026-08-19T14:48:01.168Z

Link: CVE-2026-76596

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T15:16:21.500

Modified: 2026-08-22T15:16:21.500

Link: CVE-2026-76596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T15:30:05Z

Weaknesses