CVE-2026-67284: Joomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Cloud < 2.0.2
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67284?
CVE-2026-67284 is rated with a risk score of 51, indicating a medium vulnerability.
How do I fix CVE-2026-67284?
To fix CVE-2026-67284, upgrade to Cotton Cloud version 2.0.3 or later, which addresses the improper ACL checks.
What does CVE-2026-67284 affect?
CVE-2026-67284 affects the Joomla Extension Cotton Cloud versions prior to 2.0.3, allowing improper file operations.
Who is affected by CVE-2026-67284?
Authenticated users of Cotton Cloud versions below 2.0.3 are affected as they can perform unauthorized file operations.
What type of vulnerability is CVE-2026-67284?
CVE-2026-67284 is categorized as an improper access control vulnerability that allows file-related operations on unauthorized files.