SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76600

MEDIUM · CVSS 6.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Fabrikar Joomla extension prior to version 4.7.2 is vulnerable to unauthenticated deletion of any comment due to insufficient access controls in the DeleteComment endpoint. This flaw allows an attacker to remove comments without authentication, potentially disrupting user-generated content and impacting site integrity. Joomla administrators and developers utilizing this extension should prioritize applying the latest updates to mitigate this risk.

CVE
CVE-2026-76600
Severity
MEDIUM
CVSS
6.9
EPSS
0.24%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.