Unauthenticated Row Reordering in Fabrik Extension by Fabrikar
CVE-2026-76601

6.9MEDIUM

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76601?

The Fabrik extension for Joomla is susceptible to an unauthenticated row reordering vulnerability, where the order plugin fails to conduct proper access checks. This oversight allows unauthorized users to manipulate the arrangement of data rows without authentication, potentially leading to unauthorized access to sensitive data or disruption of the normal operations of the application. It is crucial for users of Fabrik versions prior to 4.7.2 to assess their exposure to this vulnerability and take appropriate measures to secure their systems.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.