CVE-2026-88857: Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7

Published Sep 20, 2026
·
Updated

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.

Affected Software

2 affected components
OrdaSoft.com Joomla Gallery extension<6.2.7
Joomla Joomla!<6.2.7

Event History

Sep 20, 2026
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated and have the Joomla core.manage permission. This is therefore primarily exposed where privileged Joomla accounts are compromised or granted to untrusted users.

2

What does exploitation require?

The attacker uploads a PHP file through saveWatermark(), presenting it with an image Content-Type header. Because the uploaded filename is used without sanitisation or validation, the attacker can then request the file from its web-accessible location to execute it.

3

Are installations affected by default?

The available information does not establish whether the vulnerable functionality or core.manage access is enabled by default. Exploitation depends on an authenticated user holding that permission.

4

What can be done if updating is not immediately possible?

Restrict core.manage access to fully trusted accounts and review privileged accounts for compromise or unnecessary permissions. Limit or disable access to the affected upload functionality where operationally possible.

5

How can administrators look for prior exploitation?

Review the web-accessible directory used by saveWatermark() for unexpected PHP files or files with suspicious image-like names, and check web-server logs for requests to such uploaded files. Also review upload activity performed by accounts with core.manage permission.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203