Path Traversal Vulnerability in Fabrik Extension by Joomla
CVE-2026-76606

10CRITICAL

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76606?

A vulnerability in the Fabrik extension for Joomla allows attackers to exploit path traversal weaknesses through image elements, potentially accessing unauthorized files on the server. This issue is particularly concerning for installations running versions prior to 4.7.3, where insufficient validation of user inputs could lead to exposure of sensitive data and system compromise.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.3

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.