Description
Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.
Published: 2026-08-22
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability resides in the Fabrik Joomla extension, version 4.7.2 and earlier, where the onGetEmail endpoint does not perform any access checks. An attacker who knows or can guess the endpoint URL can retrieve the email address of any commenter without authentication, exposing personal data and providing a vector for spam or phishing attacks. This weakness is a classic example of improper access control (CWE-284).

Affected Systems

Affected systems are installations of the Fabrik extension from fabrikar.com for Joomla PHP CMS. Versions earlier than 4.7.2 are vulnerable. There is no evidence that later versions are affected and vendors state that 4.7.2 or newer contains the fix.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity, and the lack of an EPSS score suggests no known exploitation data yet. Because the endpoint can be queried by anyone with network access to the site, the attack vector is likely straightforward: a simple HTTP request to the onGetEmail URL. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly documented exploits exist, but the lack of authentication makes it an attractive target for privacy‑oriented attackers.

Generated by OpenCVE AI on August 22, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a Fabrik extension update to version 4.7.2 or later.
  • If upgrading is not feasible, restrict access to the onGetEmail endpoint by configuring Joomla permissions or using URL rewriting/ .htaccess rules to block unauthenticated requests.
  • Disable email collection or commenting features if they are not required, removing the exposed data source.

Generated by OpenCVE AI on August 22, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.
Title Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T13:03:15.749Z

Reserved: 2026-08-19T14:48:01.169Z

Link: CVE-2026-76608

cve-icon Vulnrichment

Updated: 2026-08-24T12:52:54.060Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:22.913

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-76608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T16:00:12Z

Weaknesses