Unauthenticated Directory Listing in Fabrik Joomla Extension
CVE-2026-76598

8.7HIGH

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76598?

The Fabrik extension for Joomla versions earlier than 4.7.2 is susceptible to an unauthenticated arbitrary directory listing vulnerability. This issue arises from the onAjax_getFolders method within the elements model, which inadvertently exposes sensitive directories to unauthorized users, potentially allowing them to access files and information that should be securely protected. It is essential for users and administrators of the Fabrik extension to upgrade to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.