CVE-2026-67283: Joomla Extension - tabaoca.org - Improper ACL implementation allows allow file operations in Cotton Cloud < 2.0.2
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67283?
The severity of CVE-2026-67283 is classified as 78, indicating a high level of risk.
How do I fix CVE-2026-67283?
To fix CVE-2026-67283, upgrade to Cotton Cloud version 2.0.2 or later as it addresses the improper ACL implementation.
What does CVE-2026-67283 allow unauthenticated users to do?
CVE-2026-67283 allows unauthenticated users to perform file operations such as reading, deleting, overwriting, and reassigning permissions on files managed within the extension.
Which version of the Joomla Extension - tabaoca.org is affected by CVE-2026-67283?
All versions of the Joomla Extension - tabaoca.org prior to 2.0.2 are affected by CVE-2026-67283.
How does the improper ACL implementation in CVE-2026-67283 impact security?
The improper ACL implementation in CVE-2026-67283 compromises security by allowing unauthorized access to critical file operations.