CVE-2026-66493: Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
Published Aug 7, 2026
·Updated
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.
Affected Software
1 affected component
Joomla Extension phoca.cz/Phoca Commander>=1.0.0<=6.1.3
Event History
Aug 7, 2026
CVE Published
via MITRE·08:03 AM
Data Sourced
via MITRE·08:03 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66493?
CVE-2026-66493 has a risk rating of 47, indicating a significant security concern.
2
How do I fix CVE-2026-66493?
To fix CVE-2026-66493, update Phoca Commander to the latest version that addresses the path traversal vulnerability.
3
What actions are affected by CVE-2026-66493?
CVE-2026-66493 affects delete, copy, and move actions within Phoca Commander due to improper path limitations.
4
What can attackers do with CVE-2026-66493?
Attackers exploiting CVE-2026-66493 can access unauthorized files on the server via path traversal.
5
Which software is impacted by CVE-2026-66493?
CVE-2026-66493 impacts the Joomla Extension Phoca Commander versions 1.0.0 to 6.1.3.