CyberRota Analysis
AI-GeneratedThe Fabrik Joomla extension versions prior to 4.7.3 are vulnerable due to a missing Access Control List (ACL) check in the download element, allowing unauthorized users to access and download sensitive files. This critical vulnerability poses a severe risk of data exposure and exploitation, making it imperative for all Joomla users utilizing the Fabrik extension to prioritize immediate updates to version 4.7.3 or later. Organizations relying on this extension should act swiftly to mitigate potential breaches.
CVE
CVE-2026-76607
Severity
CRITICAL
CVSS
10
EPSS
0.24%
Original NVD Description
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.