Remote Code Execution Vulnerability in AcyMailing Enterprise Extension by Joomla
CVE-2026-94132
9.5CRITICAL
What is CVE-2026-94132?
A remote code execution vulnerability exists in the AcyMailing Enterprise extension for Joomla, where MIME parts from incoming emails are improperly stored in the application’s media directory without extension validation. This flaw allows attackers who can send emails to the monitored mailbox to upload malicious PHP files to the web root, potentially enabling them to execute arbitrary code on the server. Users of versions prior to 11.1.0 should take immediate action to mitigate this security risk.
Affected Version(s)
AcyMailing Enterprise extension for Joomla 1.0.0-11.0.5
