SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74803

CRITICAL · CVSS 10 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated arbitrary file upload vulnerability exists in the Zoo extension for Joomla versions prior to 4.1.64, allowing attackers to upload malicious files by manipulating the Content-Type header. This critical flaw could lead to remote code execution and complete system compromise. Organizations using affected versions of the Zoo extension should prioritize immediate patching to mitigate potential exploitation.

CVE
CVE-2026-74803
Severity
CRITICAL
CVSS
10
EPSS
0.31%

Original NVD Description

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.