SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76608

MEDIUM · CVSS 6.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from fabrikar.com is vulnerable to an unauthenticated disclosure of email addresses for commenters due to insufficient access controls in the onGetEmail endpoint. This flaw allows unauthorized users to retrieve sensitive email information, potentially leading to privacy breaches and targeted attacks. Organizations using Fabrik versions prior to 4.7.2 should prioritize patching this vulnerability to protect user data.

CVE
CVE-2026-76608
Severity
MEDIUM
CVSS
6.9
EPSS
0.29%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.