Description
Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.
Published: 2026-08-22
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fabrik extension for Joomla contains a plugin that reorders database rows. The plugin performs no access checks, allowing any visitor to trigger a reorder operation. This flaw enables an unauthenticated attacker to alter the order of records, potentially changing the way content is displayed or accessed within the site. The vulnerability can be exploited to manipulate application logic, leading to data integrity violations and possible privilege escalation if ordering affects visibility or access control. The weakness is classified as CWE‑284, improper authorization.

Affected Systems

Vendors affected are fabrikar.com, which develops the Fabrik Joomla extension. The flaw exists in all versions prior to 4.7.2. Administrators should verify the installed extension version and apply an update to 4.7.2 or newer to eliminate the unchecked reordering capability.

Risk and Exploitability

With a CVSS score of 6.9, this issue presents a moderate severity risk. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalogue. Because the flaw can be exercised by unauthenticated users through the web interface, a typical attack involves sending crafted requests to the reorder endpoint. The lack of authentication checks makes exploitation straightforward, so sites running affected versions should treat it as a non‑trivial risk.

Generated by OpenCVE AI on August 22, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or later, which restores proper authorization for row reordering.
  • If an immediate upgrade is not feasible, restrict access to the reordering functionality by configuring Joomla permissions or applying server‑level access controls to prevent unauthenticated requests.
  • Monitor site logs for unexpected reorder activity and review any changes to record ordering that may indicate malicious activity.
  • If the feature is not required, disable or remove the row reordering plugin to eliminate the attack surface.

Generated by OpenCVE AI on August 22, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.
Title Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-22T14:14:18.413Z

Reserved: 2026-08-19T14:48:01.168Z

Link: CVE-2026-76601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T15:16:22.090

Modified: 2026-08-22T15:16:22.090

Link: CVE-2026-76601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T15:30:05Z

Weaknesses