Remote Code Execution Vulnerability in Fabrik Joomla Extension by Fabrikar
CVE-2026-76605

10CRITICAL

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76605?

The Fabrik Joomla extension is susceptible to a remote code execution vulnerability that allows unauthorized users to execute arbitrary code through the image element. This flaw exists in versions prior to 4.7.3, making it imperative for users to update to the latest version to mitigate potential exploitation risks. Affected users are strongly advised to review their installations and apply necessary security measures.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.3

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.