Unauthenticated SQL Injection Flaw in Fabrik Extension by Joomla
CVE-2026-76571

9.3CRITICAL

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76571?

The Fabrik Extension for Joomla is susceptible to an unauthenticated SQL injection vulnerability. This issue arises when an attacker manipulates the condition parameter of a list filter, which is directly included in the SQL WHERE clause without adequate sanitization. As a result, an unauthorized individual can execute arbitrary SQL commands, gaining full read access to the underlying database. This vulnerability emphasizes the need for secure coding practices to prevent exploitation.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.