CVE-2026-76597: Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.
Affected Software
1 affected component
fabrikar.com<4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Fabrik versions earlier than 4.7.2 are affected when the list email plugin controller is present and reachable. The issue concerns uploads written to the web root.
2
Does exploitation require authentication?
No. The vulnerability is described as unauthenticated, so an attacker does not need to log in before attempting an upload.
3
Can an attacker upload executable server-side code?
The available description states that the controller allows upload of non-executable files. It does not establish that executable files or server-side code can be uploaded.