CVE-2026-76596: Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
Affected Software
1 affected component
Fabrik fabrikar.com (Fabrik)<4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be treated as affected?
Fabrik versions earlier than 4.7.2 should be treated as affected.
2
Does an attacker need an authenticated Joomla account?
No. The affected endpoint lacks ACL checks, so a plain GET request can be used without authentication.
3
What is the impact of a successful request?
The request empties the target list's underlying table, resulting in table truncation.