CVE-2026-76604: Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.
Affected Software
1 affected component
Joomla fabrikar.com<4.7.3
Event History
Aug 22, 2026
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Fabrik versions earlier than 4.7.3 are affected. The provided information identifies this as a Joomla extension issue.
2
Does exploitation require authentication?
No. The issue is described as unauthenticated remote code execution, so an attacker does not need to authenticate before attempting exploitation.
3
What capability does an attacker gain if exploitation succeeds?
The vulnerable PHP form element can execute attacker-provided code. This can result in remote code execution on the affected installation.