CVE-2026-67282: Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8
Published Aug 12, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.
Affected Software
1 affected component
Joomla fabrikar.com (Fabrik)<4.6.8
Event History
Aug 12, 2026
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67282?
CVE-2026-67282 has a risk score of 95, indicating a high severity vulnerability.
2
How do I fix CVE-2026-67282?
To fix CVE-2026-67282, upgrade Fabrik to version 4.6.8 or later.
3
What kind of vulnerability is CVE-2026-67282?
CVE-2026-67282 is an unauthenticated remote code execution vulnerability in the Fabrik Joomla extension.
4
Who is affected by CVE-2026-67282?
Any Joomla site using Fabrik versions prior to 4.6.8 is affected by CVE-2026-67282.
5
How can CVE-2026-67282 be exploited?
CVE-2026-67282 can be exploited by an unauthenticated attacker to execute arbitrary code through the frontend listfilter model.