Remote Code Execution Vulnerability in Fabrik Joomla Extension - Fabrikar
CVE-2026-66915

10CRITICAL

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-66915?

A significant vulnerability exists in the Fabrik extension for Joomla versions prior to 4.6.7. An unauthenticated attacker can exploit the ajax_calc feature of the calc plugin, allowing them to execute arbitrary code remotely. This highlights the importance of keeping the extension updated and monitoring for potential unauthorized access.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.6.6

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moe Khalilov, LeetProtect Research
.