# CVE-2026-48939

## Summary

- **CVE ID:** CVE-2026-48939
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red)
- **CWE:** CWE-284, CWE-434
- **Published:** Jun 20, 2026
- **Last Modified:** Aug 12, 2026

## Description

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

## Affected Products

- icagenda.com — iCagenda extension for Joomla (1.0.0-3.9.14)
- icagenda.com — iCagenda extension for Joomla (4.0.0-4.0.7)
- icagenda.com — iCagenda extension for Joomla (3.2.1-4.0.7)

## References

- [CNA](https://www.icagenda.com/)
- [CISA-ADP](https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/)
- [CISA-ADP](https://www.icagenda.com/docs/changelog/icagenda-3-9-15)
- [CISA-ADP](https://www.icagenda.com/docs/changelog/icagenda-4-0-8)
- [CISA-ADP](https://github.com/Polosss/By-Poloss..-..CVE-2026-48939)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 19.73%
- **EPSS Percentile:** 97.2

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Jul 10, 2026
- **Due Date:** Jul 13, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._