CVE-2026-76607
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.24%
- CWE
- CWE-284
- Published
- 2026-08-22
- Last modified
- 2026-08-24
Affected products
- fabrikar.com Fabrik extension for Joomla
- fabrikar.com Fabrik extension for Joomla
Weakness type
Related vulnerabilities
- CVE-2026-65182 — Apache Tomcat: Bypass longest prefix security constraint
- CVE-2026-54745 — Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true
- CVE-2026-20315 — Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities
- CVE-2026-20192 — Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities
- CVE-2026-77553 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-77536 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-77534 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
- CVE-2026-20332 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities