SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76601

MEDIUM · CVSS 6.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Fabrik extension for Joomla versions prior to 4.7.2 is vulnerable to unauthenticated row reordering due to a lack of access checks in the order plugin. This flaw allows attackers to manipulate data presentation without authentication, potentially leading to data integrity issues. Joomla administrators using affected versions should prioritize applying the update to mitigate this risk.

CVE
CVE-2026-76601
Severity
MEDIUM
CVSS
6.9
EPSS
0.29%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.