SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76602

CRITICAL · CVSS 9.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in the Fabrik Joomla extension, affecting versions prior to 4.7.3, due to insufficient validation of the order parameter in list models. This flaw allows attackers to manipulate SQL queries, potentially leading to unauthorized data access. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-76602
Severity
CRITICAL
CVSS
9.3
EPSS
0.25%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.