Unauthenticated Table Truncation in Fabrik Extension by Joomla
CVE-2026-76596
8.7HIGH
What is CVE-2026-76596?
The Fabrik extension for Joomla contains a critical vulnerability that permits unauthenticated users to truncate database tables through the list.doempty endpoint. The absence of access control lists (ACL) enables malicious actors to execute a simple GET request, resulting in potential data loss by emptying target lists without any authentication process. This flaw affects all versions prior to 4.7.2, urging users to update to mitigate risks.
Affected Version(s)
Fabrik extension for Joomla 1.0.0-4.7.1
