Authenticated Remote Code Execution in OrdaSoft Joomla Gallery Extension
CVE-2026-88857
9.4CRITICAL
What is CVE-2026-88857?
The OrdaSoft Joomla Gallery extension is susceptible to an authenticated, privileged remote code execution vulnerability. This issue arises because the extension's saveWatermark() function allows an authenticated core.manage user to upload files directly to a web-accessible directory, utilizing the filename provided by the client without any checks for file extension, content, or sanitization. This flaw enables malicious actors to upload a potentially harmful .php file disguised as an image, posing significant security risks to Joomla installations running versions prior to 6.2.7.
Affected Version(s)
OrdaSoft Joomla Gallery extension for Joomla 1.0.0-6.2.6
OrdaSoft Joomla Gallery free extension for Joomla 1.0.0-6.2.6
