CVE-2026-77992: Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
Affected Software
1 affected component
Joomla Extension - fabrikar.com fabrikar.com<4.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla Extension - fabrikar.com (Fabrik)to a version that resolves this vulnerability.Fixed in 4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What versions are affected?
Fabrik versions earlier than 4.7.2 are affected.
2
What access does an attacker need?
The affected onUpdateComment endpoint did not perform access checks, so exploitation does not require passing that endpoint's access-control validation.
3
What is the impact of successful exploitation?
The issue is categorized as code injection and involves breaking out of a heredoc terminator in the calc element.