CVE-2026-76598: Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjaxgetFolders in Fabrik < 4.7.2 - The onAjaxgetFolders method of the elements model allows arbitrary directory listings.
Affected Software
1 affected component
Joomla fabrikar.com Fabrik<4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The affected software is the Fabrik extension for Joomla from fabrikar.com. Versions earlier than 4.7.2 are affected.
2
Does exploitation require authentication?
No. The issue is described as unauthenticated, so an attacker does not need to log in before invoking the affected functionality.
3
What information could an attacker obtain?
An attacker can obtain directory listings through the elements model's onAjax_getFolders method. The provided information does not establish that file contents can be read or modified.