SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77992

CRITICAL · CVSS 9.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Joomla Extension from fabrikar.com is vulnerable due to a heredoc terminator breakout in the calc element, specifically in versions prior to 4.7.2, which allows unauthorized access through the onUpdateComment endpoint without proper access checks. This critical vulnerability (CVSS 9.5) could lead to arbitrary code execution or data manipulation, posing significant risks to affected Joomla installations. Organizations using this extension should prioritize immediate updates to version 4.7.2 or later to mitigate potential exploitation.

CVE
CVE-2026-77992
Severity
CRITICAL
CVSS
9.5
EPSS
0.26%

Original NVD Description

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.