CVE-2026-73373

8.9

Joomla · Joomla! CMS

Joomla! CMS and Framework Filesystem are vulnerable to unrestricted file uploads, potentially allowing attackers to upload SHTML files.

Executive summary

A high-severity vulnerability in Joomla! CMS allows authenticated attackers with administrative privileges to upload dangerous SHTML files, leading to potential system compromise.

Vulnerability

This is an unrestricted file upload vulnerability (CWE-434). The vulnerability requires high privileges (PR:H) to execute, meaning an attacker must have administrative access to the platform to exploit this flaw.

Business impact

Successful exploitation allows an attacker to upload malicious SHTML files, which can lead to remote code execution and total system compromise. Given the CVSS score of 8.9, the impact on confidentiality, integrity, and availability is critical, potentially resulting in unauthorized data access and complete service disruption.

Remediation

Immediate Action: Review the official Joomla security center for available patches and apply them to all affected CMS and Framework instances immediately.

Proactive Monitoring: Audit web server directories for unauthorized SHTML files and monitor administrative logs for suspicious file upload activity.

Compensating Controls: Implement strict file type validation at the Web Application Firewall (WAF) level to block uploads of executable or server-side script files.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to the integrity of the Joomla environment. Organizations should prioritize patching as soon as the vendor releases the necessary updates to prevent potential administrative abuse and lateral movement within the hosting infrastructure.

More Joomla CVEs