Path Traversal Vulnerability in Joomla 6.1.1 Affects com_joomlaupdate Extension
CVE-2026-73327

8.7HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73327?

Joomla 6.1.1 introduces a path traversal vulnerability in the com_joomlaupdate extension, enabling a Super User to be tricked into executing malicious ZIP files. Attackers can exploit this flaw by crafting ZIP entry filenames with directory traversal sequences or absolute paths, allowing files to be extracted to unintended locations. This could lead to persistent remote code execution by deploying unauthorized PHP files outside the designated root directory.

Affected Version(s)

Joomla! CMS 0 <= 6.1.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jashn Wahi
.