Arbitrary File Upload Vulnerability in Joomla Extension JMedia
CVE-2026-60032
9.4CRITICAL
What is CVE-2026-60032?
The Joomla extension JMedia is prone to a security risk that allows authenticated users to upload arbitrary files. This vulnerability may enable unauthorized access to execute files on the server, potentially leading to Remote Code Execution (RCE). The flaw arises because file uploads are not properly validated, allowing for executable files to be uploaded with polyglot filenames. Furthermore, the permissions are not adequately restricted after uploading, as the chmod function fails to remove execute permissions, posing a significant risk to the application's integrity and security.
Affected Version(s)
JMedia extension for Joomla 1.0-1.5.4
