Description
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.
Published: 2026-08-22
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Upload to Web Root
Action: Immediate Patch
AI Analysis

Impact

The Fabrik extension for Joomla version 4.7.2 or earlier contains an unauthenticated arbitrary file upload flaw in the list email plugin controller. The flaw allows an attacker to upload any non‑executable file to the webroot without authentication. While the upload accepts only non‑executable files, a malicious user could still upload a script or other executable code in disguise or rely on server configuration that treats the upload as executable, leading to potential remote code execution or data exfiltration. This vulnerability can be leveraged by an attacker to store malicious files on the affected server, from which further attacks such as privilege escalation, data theft, or denial of service could be performed. The weakness is a classic example of improper access control (CWE‑284). Based on the description, it is inferred that malicious actors could attempt to disguise executable payloads as non‑executable files, increasing the risk of remote code execution depending on server configuration. It is also inferred that the stored malicious files might serve as footholds for further attacks including privilege escalation or data exfiltration.

Affected Systems

Affecting the Fabrikar.com Fabrik extension for Joomla. All releases of the extension prior to version 4.7.2 are impacted. No specific patch version is provided, but the recommendation is to apply any update that moves the package beyond 4.7.2.

Risk and Exploitability

The CVSS score of 8.7 classifies this issue as high severity, reflecting an unauthenticated, remote attack path. Because the exploit does not require authentication and can be carried out over HTTP, the likelihood of exploitation is elevated in environments where the Joomla site is publicly reachable and the plugin is enabled. EPSS data are not available, and the vulnerability is not listed in CISA KEV. The absolute lack of authentication allows an attacker to simply send a crafted HTTP request to the list email plugin endpoint and cause a file upload to the web root, potentially leading to remote code execution depending on server configuration. Based on the description, it is inferred that the likely attack vector is sending an unauthenticated HTTP request to the list email plugin endpoint. The absence of authentication and the fact that the upload accepts only non‑executable files suggests that an attacker could still attempt to exploit server configurations that misinterpret these files, thereby potentially achieving remote code execution or data exfiltration.

Generated by OpenCVE AI on August 22, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or later to remove the flawed upload endpoint.
  • If an immediate upgrade is not feasible, disable the list email plugin or restrict its access using Joomla’s ACL or a firewall rule so that only privileged users can invoke the upload functionality.
  • In addition, configure the web server to disallow execution of files in the upload directory and reject dangerous file extensions such as .php, .jsp, .asp, or .cgi, and enforce strict MIME type validation.

Generated by OpenCVE AI on August 22, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.
Title Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T13:09:13.102Z

Reserved: 2026-08-19T14:48:01.168Z

Link: CVE-2026-76597

cve-icon Vulnrichment

Updated: 2026-08-24T12:51:58.637Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:21.620

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-76597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T16:00:13Z

Weaknesses