Arbitrary File Upload Vulnerability in Joomla Extension JMedia
CVE-2026-60032

9.4CRITICAL

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-60032?

The Joomla extension JMedia is prone to a security risk that allows authenticated users to upload arbitrary files. This vulnerability may enable unauthorized access to execute files on the server, potentially leading to Remote Code Execution (RCE). The flaw arises because file uploads are not properly validated, allowing for executable files to be uploaded with polyglot filenames. Furthermore, the permissions are not adequately restricted after uploading, as the chmod function fails to remove execute permissions, posing a significant risk to the application's integrity and security.

Affected Version(s)

JMedia extension for Joomla 1.0-1.5.4

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.