CVE-2026-66491: Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
Published Aug 7, 2026
·Updated
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
Affected Software
1 affected component
Phoca Commander>=1.0.0<=6.1.3
Event History
Aug 7, 2026
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66491?
CVE-2026-66491 has a risk rating of 56, indicating a moderate severity.
2
How do I fix CVE-2026-66491?
To mitigate CVE-2026-66491, update Phoca Commander to the latest version where the arbitrary file read vulnerability is patched.
3
What type of vulnerability is CVE-2026-66491?
CVE-2026-66491 is classified as a Path Traversal vulnerability.
4
Which versions of Phoca Commander are affected by CVE-2026-66491?
CVE-2026-66491 affects Phoca Commander versions 1.0.0 through 6.1.3.
5
What can attackers exploit in CVE-2026-66491?
Attackers can exploit CVE-2026-66491 to read arbitrary files on the server due to improper path limitations in the getSource function.