Improper ACL Implementation in Cotton Cloud by tabaoca.org
CVE-2026-67283

6.9MEDIUM

Key Information:

Vendor
CVE Published:
12 August 2026

What is CVE-2026-67283?

The Cotton Cloud extension developed by tabaoca.org exhibits a serious flaw in its Access Control List (ACL) implementation. This vulnerability allows unauthenticated users to execute various unauthorized file operations such as reading, deleting, overwriting files, and altering permissions on all files managed by the extension. This poses a significant risk to the integrity and confidentiality of user data.

Affected Version(s)

Cotton Cloud extension for Joomla 1.0.0-2.0.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.