Unauthenticated Database Table Disclosure in Fabrik Extension by Joomla
CVE-2026-76599

8.7HIGH

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76599?

The Fabrik Extension for Joomla prior to version 4.7.2 presents a significant security flaw whereby the ajax_tables method in the elements model permits unauthorized users to list arbitrary database tables and their respective columns. This vulnerability can lead to sensitive information exposure, making it imperative for users to update to the latest version to secure their web applications.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.