Authenticated Remote Code Execution in OrdaSoft Joomla Gallery Extension
CVE-2026-88856

9.4CRITICAL

What is CVE-2026-88856?

The OrdaSoft Joomla Gallery extension contains a critical vulnerability that allows authenticated users to execute arbitrary PHP code on the server. Through the updateOSGallery() function, accessible via a specific task, the extension processes JSON input without proper validation. This includes calling any function specified in the request, such as system commands, which poses a severe risk of full server compromise. Users are encouraged to update to version 6.2.7 or later to mitigate this risk.

Affected Version(s)

OrdaSoft Joomla Gallery extension for Joomla 1.0.0-6.2.6

OrdaSoft Joomla Gallery free extension for Joomla 1.0.0-6.2.6

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.