SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76609

MEDIUM · CVSS 6.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from fabrikar.com is vulnerable to unauthenticated modification of comments due to insufficient access controls on the onUpdateComment endpoint in versions prior to 4.7.2. This flaw allows attackers to alter comments without authentication, potentially leading to misinformation or reputational damage. Organizations using this extension should prioritize updating to version 4.7.2 or later to mitigate the risk.

CVE
CVE-2026-76609
Severity
MEDIUM
CVSS
6.9
EPSS
0.24%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.