CyberRota Analysis
AI-GeneratedThe Joomla Extension from fabrikar.com is vulnerable to unauthenticated arbitrary directory listing due to the onAjax_getFolders method in versions prior to 4.7.2. This flaw allows attackers to access sensitive directory structures, potentially exposing critical information. Organizations using this extension should prioritize patching to mitigate the risk of data exposure and unauthorized access.
CVE
CVE-2026-76598
Severity
HIGH
CVSS
8.7
EPSS
0.31%
Original NVD Description
Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.