Description
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
Published: 2026-08-22
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Table truncation leading to data loss and service disruption
Action: Immediate Patch
AI Analysis

Impact

The Fabrik extension for Joomla contains an unauthenticated endpoint, list.doempty, that lacks any access‑control checks. An attacker can issue a plain HTTP GET request to this endpoint, which triggers the emptying of the target list’s database table. The result is irreversible data loss for the affected list and potential interruption of services that rely on that data. This flaw is a classic Broken Access Control vulnerability (CWE‑284).

Affected Systems

Any site running the Fabrik extension for Joomla with a version prior to 4.7.2 is affected. No specific sub‑versions were enumerated, but all releases below 4.7.2 should be considered vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The attacker’s path requires only unauthenticated HTTP access to the targeted site, making exploitation trivial for anyone with network visibility to the Joomla installation. Once triggered, the data is permanently lost, and no user‑level authentication is needed to perform the attack.

Generated by OpenCVE AI on August 22, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or later, which removes the unauthenticated list.doempty endpoint.
  • If an upgrade cannot be performed immediately, reconfigure Joomla ACL settings to require authentication for list.doempty or remove the functionality through custom code.
  • Block unauthenticated GET requests to list.doempty using a web server rule or firewall to prevent the truncation until a patch or configuration change is applied.

Generated by OpenCVE AI on August 22, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
Title Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T13:08:49.073Z

Reserved: 2026-08-19T14:48:01.168Z

Link: CVE-2026-76596

cve-icon Vulnrichment

Updated: 2026-08-24T12:52:17.054Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:21.500

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-76596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T15:45:03Z

Weaknesses