Description
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a package field as its single argument, with no allow-list or is_callable() check of any kind. Any function name compatible with a single argument was directly reachable, including system, exec, shell_exec, and passthru.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated, Privileged Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the OrdaSoft Joomla Gallery extension for Joomla. An authenticated user with sufficient privileges can instruct the extension to execute an arbitrary PHP function by sending a specially crafted JSON payload to the updateOSGallery task. Because the extension directly interprets the value of a method field as a live PHP function without any allow‑list or is_callable() check, functions such as system, exec, shell_exec, and passthru can be invoked. This flaw provides remote code execution on the web server, allowing an attacker to compromise the host, install malware, exfiltrate data, or pivot to other systems. The weakness is a classic example of code injection, mapped to CWE‑94.

Affected Systems

The flaw affects the OrdaSoft Joomla Gallery extension (both paid and free variants) for Joomla versions earlier than 6.2.7. Attackers must be able to authenticate to the Joomla site and possess privileged access to invoke the updateOSGallery task. No other vendors or product families are cited as impacted.

Risk and Exploitability

The CVSS score of 9.4 indicates delivery, installation, execution, and exfiltration capabilities are all satisfied, and the flaw is exploitable locally in the context of the web application. The EPSS score is not available, but the absence of a listing in the CISA KEV catalog does not diminish the severity of the flaw. The likely attack vector is through a normal Joomla session with administrative privileges enabling the updateOSGallery task. The lack of any additional verification or function whitelisting makes exploitation straightforward for a knowledgeable attacker.

Generated by OpenCVE AI on September 20, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the OrdaSoft Joomla Gallery extension to version 6.2.7 or later, or uninstall the extension if an upgrade is not available.
  • Restrict the updateOSGallery task so that only the highest‑privilege site administrators can invoke it, or temporarily disable the task until the official patch can be applied.
  • Configure the PHP runtime to disable dangerous functions such as exec, shell_exec, and passthru—or otherwise enforce a whitelist of allowed functions—so that even if the extension misuses a function name, execution of system‑level commands is blocked.

Generated by OpenCVE AI on September 20, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.OrdaSoft.com/ cve-icon cve-icon
History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Ordasoft.com
Ordasoft.com ordasoft Joomla Gallery Extension For Joomla
Ordasoft.com ordasoft Joomla Gallery Free Extension For Joomla
Vendors & Products Ordasoft.com
Ordasoft.com ordasoft Joomla Gallery Extension For Joomla
Ordasoft.com ordasoft Joomla Gallery Free Extension For Joomla

Sun, 20 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a package field as its single argument, with no allow-list or is_callable() check of any kind. Any function name compatible with a single argument was directly reachable, including system, exec, shell_exec, and passthru.
Title Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Ordasoft.com Ordasoft Joomla Gallery Extension For Joomla Ordasoft Joomla Gallery Free Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-22T04:43:35.909Z

Reserved: 2026-09-10T10:27:00.130Z

Link: CVE-2026-88856

cve-icon Vulnrichment

Updated: 2026-09-21T14:06:08.283Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T18:16:54.280

Modified: 2026-09-22T19:34:57.263

Link: CVE-2026-88856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:22Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')