Authenticated Remote Code Execution in OrdaSoft Joomla Gallery Extension
CVE-2026-88856
9.4CRITICAL
What is CVE-2026-88856?
The OrdaSoft Joomla Gallery extension contains a critical vulnerability that allows authenticated users to execute arbitrary PHP code on the server. Through the updateOSGallery() function, accessible via a specific task, the extension processes JSON input without proper validation. This includes calling any function specified in the request, such as system commands, which poses a severe risk of full server compromise. Users are encouraged to update to version 6.2.7 or later to mitigate this risk.
Affected Version(s)
OrdaSoft Joomla Gallery extension for Joomla 1.0.0-6.2.6
OrdaSoft Joomla Gallery free extension for Joomla 1.0.0-6.2.6
