Missing Access Control in Fabrik Extension by Joomla
CVE-2026-76607

10CRITICAL

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-76607?

The Fabrik extension for Joomla is susceptible to a security issue due to a missing Access Control List (ACL) check in the download element. This vulnerability allows unauthorized users to access and download files that should be restricted. Versions prior to 4.7.3 are affected, emphasizing the need for users to update their installations to mitigate potential exploitation.

Affected Version(s)

Fabrik extension for Joomla 1.0.0-4.7.3

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.