Improper ACL Implementation in Cotton Cloud by tabaoca.org
CVE-2026-67283
6.9MEDIUM
What is CVE-2026-67283?
The Cotton Cloud extension developed by tabaoca.org exhibits a serious flaw in its Access Control List (ACL) implementation. This vulnerability allows unauthenticated users to execute various unauthorized file operations such as reading, deleting, overwriting files, and altering permissions on all files managed by the extension. This poses a significant risk to the integrity and confidentiality of user data.
Affected Version(s)
Cotton Cloud extension for Joomla 1.0.0-2.0.1
