Description
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
Published: 2026-08-22
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Fabrik extension for Joomla in versions earlier than 4.7.2 allows an attacker to craft a malicious string that exploits a heredoc terminator breakout in its calc element, enabling execution of arbitrary PHP code and resulting in full remote code execution. The vulnerability is further aggravated because the onUpdateComment endpoint does not perform any access checks, meaning an unauthenticated or low‑privileged user can trigger the flaw.

Affected Systems

The affected component is the Fabrik extension for Joomla, with all releases prior to version 4.7.2 exposed to the vulnerability. Deployments that run the extension on any Joomla site, regardless of installed user roles, must confirm the version in use and update accordingly.

Risk and Exploitability

The CVSS score of 9.5 indicates a critical rating. Although an EPSS score is not available, the absence of a KEV listing does not diminish the potential for widespread exploitation, especially given the lack of access controls. Attackers can leverage the unauthenticated onUpdateComment endpoint to trigger the RCE, making this risk high in both severity and likelihood for exposed Joomla sites.

Generated by OpenCVE AI on August 22, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fabrik extension to version 4.7.2 or newer.
  • Restrict the onUpdateComment endpoint so that only authorized users can invoke it, such as by applying Joomla user group permissions or server‑side access controls.
  • If an immediate upgrade is not possible, block or rate‑limit HTTP requests to the /onUpdateComment endpoint to prevent exploitation until a patch is applied.

Generated by OpenCVE AI on August 22, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.fabrikar.com/ cve-icon cve-icon
History

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabrikar.com
Fabrikar.com fabrik Extension For Joomla
Vendors & Products Fabrikar.com
Fabrikar.com fabrik Extension For Joomla

Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
Title Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Fabrikar.com Fabrik Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T13:08:44.449Z

Reserved: 2026-08-21T19:05:09.013Z

Link: CVE-2026-77992

cve-icon Vulnrichment

Updated: 2026-08-24T12:52:23.333Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T15:16:23.293

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-77992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T15:45:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')