Authenticated Remote Code Execution in OrdaSoft Joomla Gallery Extension
CVE-2026-88857

9.4CRITICAL

What is CVE-2026-88857?

The OrdaSoft Joomla Gallery extension is susceptible to an authenticated, privileged remote code execution vulnerability. This issue arises because the extension's saveWatermark() function allows an authenticated core.manage user to upload files directly to a web-accessible directory, utilizing the filename provided by the client without any checks for file extension, content, or sanitization. This flaw enables malicious actors to upload a potentially harmful .php file disguised as an image, posing significant security risks to Joomla installations running versions prior to 6.2.7.

Affected Version(s)

OrdaSoft Joomla Gallery extension for Joomla 1.0.0-6.2.6

OrdaSoft Joomla Gallery free extension for Joomla 1.0.0-6.2.6

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.