SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76599

HIGH · CVSS 8.7 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Fabrik extension for Joomla versions prior to 4.7.2 is vulnerable to unauthenticated access, allowing attackers to list arbitrary database tables and their columns through the ajax_tables method. This exposure could lead to sensitive data disclosure and potential exploitation of the underlying database. Joomla administrators and developers using this extension should prioritize applying the latest update to mitigate the risk.

CVE
CVE-2026-76599
Severity
HIGH
CVSS
8.7
EPSS
0.29%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.