Description
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
Published: 2026-08-22
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read
Action: Immediate Patch
AI Analysis

Impact

The Fabrik extension for Joomla contains a path traversal vulnerability in the handling of image elements in versions older than 4.7.2. An attacker can craft an image parameter that resolves to arbitrary filesystem paths, allowing the reading of files not intended to be publicly accessible. This can expose sensitive files, configuration data, or other information, compromising confidentiality and potentially enabling further exploitation.

Affected Systems

Fabrik extension for Joomla by fabrikar.com is affected in all releases prior to 4.7.3. Websites running these versions are vulnerable.

Risk and Exploitability

The CVSS score of 10 indicates an extremely high risk. Although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog yet, but the severity suggests a high likelihood of exploitation, especially on sites that allow users to upload or specify image elements. The likely attack vector is through the web interface, where an attacker can embed a malicious image element in a form or content that triggers the path traversal.

Generated by OpenCVE AI on August 23, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.3 or later.
  • If upgrading immediately is not possible, configure the image element handling to restrict file paths to trusted directories and enable input validation to eliminate traversal sequences.
  • Set appropriate file system permissions on the Joomla installation to prevent web users from reading sensitive files outside the web root.

Generated by OpenCVE AI on August 23, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 23 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???. Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
Title Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2

Sat, 22 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
Title Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T13:11:40.431Z

Reserved: 2026-08-19T14:48:01.169Z

Link: CVE-2026-76606

cve-icon Vulnrichment

Updated: 2026-08-24T12:51:38.957Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:22.680

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-76606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T12:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')