Improper Access Control in Joomla Extension by Tabaoca
CVE-2026-67284
5.3MEDIUM
What is CVE-2026-67284?
The Joomla extension from Tabaoca exhibits an improper implementation of Access Control Lists (ACL), allowing authenticated users to execute unauthorized file operations, such as reading, deleting, and overwriting files that belong to other users. This vulnerability affects versions of Cotton Cloud below 2.0.3, posing significant security risks if left unaddressed.
Affected Version(s)
Cotton Cloud extension for Joomla 1.0.0-2.0.2
