CyberRota Analysis
AI-GeneratedThe Joomla Extension from fabrikar.com is vulnerable to an unauthenticated disclosure of email addresses for commenters due to insufficient access controls in the onGetEmail endpoint. This flaw allows unauthorized users to retrieve sensitive email information, potentially leading to privacy breaches and targeted attacks. Organizations using Fabrik versions prior to 4.7.2 should prioritize patching this vulnerability to protect user data.
CVE
CVE-2026-76608
Severity
MEDIUM
CVSS
6.9
EPSS
0.29%
Original NVD Description
Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.