CyberRota Analysis
AI-GeneratedAn unauthenticated SQL injection vulnerability exists in the Fabrik Joomla extension, affecting versions prior to 4.7.3, due to insufficient validation of the order parameter in list models. This flaw allows attackers to manipulate SQL queries, potentially leading to unauthorized data access. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.
CVE
CVE-2026-76602
Severity
CRITICAL
CVSS
9.3
EPSS
0.25%
Original NVD Description
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.