Unauthenticated File Deletion in AcyMailing Enterprise Extension by Joomla
CVE-2026-94131
8.3HIGH
What is CVE-2026-94131?
The AcyMailing Enterprise extension for Joomla contains a vulnerability that allows unauthenticated users to exploit file-type custom fields to perform arbitrary file deletions. By storing a file path in a custom field and subsequently clearing that field, harmful actions can be taken that lead to the deletion of critical files, including those located outside the intended upload folder, such as configuration files. This oversight poses a significant risk to site security and data integrity.
Affected Version(s)
AcyMailing extension for Joomla 1.0.0-11.0.5
