CVE-2026-67282
10.0fabrikar.com · Fabrik extension for Joomla
The Fabrik extension for Joomla contains an unauthenticated remote code execution vulnerability within its frontend listfilter model.
Executive summary
An unauthenticated remote code execution vulnerability in the Fabrik extension for Joomla, rated at 10.0, allows attackers to gain full control of the host system.
Vulnerability
This vulnerability involves improper control over code generation, allowing an unauthenticated attacker to inject and execute arbitrary code via the frontend listfilter model. It is a critical flaw that bypasses all standard authentication mechanisms.
Business impact
The ability for an unauthenticated user to execute arbitrary code on a server is a worst-case security scenario, leading to total system compromise, data theft, and potential lateral movement within the network. With a CVSS score of 10.0, this vulnerability must be treated as an emergency, as it provides a direct path for attackers to gain administrative control over the Joomla environment.
Remediation
Immediate Action: Update the Fabrik extension to version 4.6.8 or later immediately to address the code injection vulnerability.
Proactive Monitoring: Inspect web server logs for suspicious POST requests targeting the listfilter model or unusual patterns indicative of remote code execution attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to block malicious payloads targeting Joomla extensions until the patch can be applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Administrators must treat this vulnerability with the highest level of urgency. Given the ease of access and the severity of the potential impact, all instances of the Fabrik extension must be updated to the patched version as soon as possible to prevent full site takeover.