Unauthenticated SQL Injection Vulnerability in Fabrik Extension by Joomla
CVE-2026-76602

9.3CRITICAL

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76602?

The Fabrik extension for Joomla is vulnerable to an unauthenticated SQL injection attack due to improper validation of the order parameter in list models. This vulnerability can be exploited by attackers to perform unauthorized SQL queries and manipulate database records, potentially leading to data exposure and integrity issues. Users of Fabrik versions below 4.7.3 should take immediate action to secure their instances and apply necessary updates.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.