CVE-2026-76599: Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajaxtables method of the elements model allows listings of arbitrary database tables including columns.
Affected Software
1 affected component
Joomla fabrikar.com Fabrik<4.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
fabrikar.comto a version that resolves this vulnerability.Fixed in 4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Joomla sites using the Fabrik extension below version 4.7.2 are affected. The issue is described as unauthenticated, so exposure does not depend on an attacker having a Joomla account.
2
What information can an attacker obtain?
An attacker can invoke the elements model's ajax_tables method to list arbitrary database tables and their columns. The disclosure also includes the database table prefix.