Remote Code Execution Vulnerability in AcyMailing Enterprise Extension by Joomla
CVE-2026-94132

9.5CRITICAL

Key Information:

Vendor
CVE Published:
26 September 2026

What is CVE-2026-94132?

A remote code execution vulnerability exists in the AcyMailing Enterprise extension for Joomla, where MIME parts from incoming emails are improperly stored in the application’s media directory without extension validation. This flaw allows attackers who can send emails to the monitored mailbox to upload malicious PHP files to the web root, potentially enabling them to execute arbitrary code on the server. Users of versions prior to 11.1.0 should take immediate action to mitigate this security risk.

Affected Version(s)

AcyMailing Enterprise extension for Joomla 1.0.0-11.0.5

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.