# CVE-2026-84048

## Summary

- **CVE ID:** CVE-2026-84048
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A)
- **CWE:** CWE-284
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 16, 2026

## Description

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.

## Affected Products

- joomgalleryfriends.net — JoomGallery extension for Joomla (4.0.0-4.4.1)

## References

- [CNA](https://www.joomgalleryfriends.net/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 23.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._