Description
Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.
Published: 2026-08-22
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure
Action: Patch Immediately
AI Analysis

Impact

The Fabrik extension for Joomla version prior to 4.7.2 contains an unauthenticated data disclosure flaw in the ajax_tables method of its elements model. An attacker can invoke this publicly accessible AJAX endpoint and retrieve a list of all database tables along with their prefixes. This exposure allows enumeration of all tables that might contain user accounts, configuration settings, and other sensitive site data, thereby compromising confidentiality.

Affected Systems

Joomla sites that host the Fabrikar.com Fabrik extension at any version lower than 4.7.2 are impacted. No other vendors or product versions are identified in the CVE data.

Risk and Exploitability

With a CVSS score of 8.7 the vulnerability is rated high severity. The exploitation requires no login and is triggered through a standard web request to the ajax_tables interface, so the likelihood of a real-world attack is significant. The EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, but the absence of those factors does not mitigate the inherent risk presented by the unauthenticated access to database metadata.

Generated by OpenCVE AI on August 22, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or newer, where the ajax_tables method is secured to require authentication.
  • If an immediate upgrade is not feasible, restrict the ajax_tables endpoint by configuring the site’s access control to allow the call only from authenticated users or by blocking anonymous access to all AJAX interfaces.
  • Delete or disable any custom or third‑party AJAX routes that expose database information on the site.

Generated by OpenCVE AI on August 22, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.
Title Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-25T04:44:36.518Z

Reserved: 2026-08-19T14:48:01.168Z

Link: CVE-2026-76599

cve-icon Vulnrichment

Updated: 2026-08-24T18:30:49.238Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:21.857

Modified: 2026-08-26T16:36:16.990

Link: CVE-2026-76599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T16:00:13Z

Weaknesses