Description
Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.
Published: 2026-08-22
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated deletion of comments, resulting in loss of data integrity
Action: Patch Immediately
AI Analysis

Impact

The DeleteComment endpoint does not perform any access checks, allowing any user to delete any comment in Fabrik versions older than 4.7.2. This results in loss of data integrity and potential defacement or loss of user feedback. The weakness is an unauthorized deletion control flaw (CWE-284).

Affected Systems

The vulnerability affects the Fabrik extension for Joomla provided by fabrikar.com for all versions prior to 4.7.2. No specific sub‑versions are listed, so any installation using a vulnerable release is impacted.

Risk and Exploitability

With a CVSS score of 6.9 the risk is moderate. The EPSS score is not reported, and the flaw is not currently listed in CISA KEV. The endpoint is accessible without authentication, so an attacker can trigger deletion remotely by sending a request to DeleteComment. No additional conditions are specified in the report.

Generated by OpenCVE AI on August 22, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or newer.
  • If an upgrade is not feasible, limit the DeleteComment endpoint to users with administrative privileges or apply an IP whitelist to restrict access.
  • Modify Fabrik settings to disable DeleteComment for non‑admin roles.

Generated by OpenCVE AI on August 22, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.
Title Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T13:07:27.591Z

Reserved: 2026-08-19T14:48:01.168Z

Link: CVE-2026-76600

cve-icon Vulnrichment

Updated: 2026-08-24T12:52:29.332Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:21.970

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-76600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T16:00:13Z

Weaknesses