Unauthenticated Remote Code Execution in Joomla Extension by Fabrikar
CVE-2026-67282

10CRITICAL

Key Information:

Vendor
CVE Published:
12 August 2026

What is CVE-2026-67282?

The Fabrik extension for Joomla is vulnerable to unauthenticated remote code execution. Attackers exploit this vulnerability through the frontend listfilter model, allowing unauthorized users to execute arbitrary code on the server. This can lead to serious security breaches, making it imperative for users to update their installations to Fabrik version 4.6.8 or later to mitigate risks.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.6.7

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Murad Gasimov
.