Description
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.
Published: 2026-09-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The OrdaSoft Joomla Gallery extension copies an uploaded file into a web‑accessible directory without checking the file extension, verifying content, or sanitizing the file name. An attacker who is an authenticated core.manage user can therefore upload a PHP file disguised with an image Content‑Type header and later execute it by accessing the resulting URL. This flaw allows full remote code execution on the affected system, compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability is confined to OrdaSoft.com’s Joomla Gallery extension for Joomla, in both the paid and free variants. All releases older than version 6.2.7 are affected. Exploitation requires an authenticated account with core.manage privileges, so the impact is limited to sites that grant such rights to users who should not be able to upload arbitrary files.

Risk and Exploitability

The CVSS score of 9.4 categorises the issue as critical. Although the EPSS score is not available, the absence of any file‑type or content validation, coupled with the ability to write files to a public directory, means attacks could be launched with little effort. The vulnerability is not yet listed in CISA’s KEV catalog, but the potential for widespread exploitation remains high.

Generated by OpenCVE AI on September 20, 2026 at 19:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the OrdaSoft Joomla Gallery extension to version 6.2.7 or later, which implements proper file‑type validation and filename sanitisation.
  • If an upgrade cannot be performed immediately, disable or remove the upload capability for users who do not have core.manage rights, preventing the upload of arbitrary files.
  • Implement server‑side controls to reject non‑image content and to strip or rename any PHP files that reach the public upload directory, and configure the web server to forbid script execution in that directory.

Generated by OpenCVE AI on September 20, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.OrdaSoft.com/ cve-icon cve-icon
History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Ordasoft.com
Ordasoft.com ordasoft Joomla Gallery Extension For Joomla
Ordasoft.com ordasoft Joomla Gallery Free Extension For Joomla
Vendors & Products Ordasoft.com
Ordasoft.com ordasoft Joomla Gallery Extension For Joomla
Ordasoft.com ordasoft Joomla Gallery Free Extension For Joomla

Sun, 20 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.
Title Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Ordasoft.com Ordasoft Joomla Gallery Extension For Joomla Ordasoft Joomla Gallery Free Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-22T04:48:00.648Z

Reserved: 2026-09-10T10:27:00.130Z

Link: CVE-2026-88857

cve-icon Vulnrichment

Updated: 2026-09-21T16:25:31.195Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T18:16:54.443

Modified: 2026-09-22T19:34:57.263

Link: CVE-2026-88857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:13Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type