CVE-2026-76600: Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.
Affected Software
1 affected component
fabrikar.com<4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The affected DeleteComment endpoint did not perform access checks, so authentication is not required to delete comments through that endpoint.
2
Which deployments are affected?
Fabrik versions earlier than 4.7.2 are affected. The available information does not identify any configuration prerequisite or mitigation other than using version 4.7.2 or later.