What is CVE-2026-66491?
CVE-2026-66491 is a critical arbitrary file read vulnerability in the Phoca Commander extension (versions 1.0.0 through 6.1.3) for Joomla. The flaw resides in the `getSource` function due to improper path limitation, allowing unauthenticated remote attackers to read arbitrary files on the host. Immediate update to the latest version is strongly recommended for all affected Joomla sites.
Azərbaycanca: CVE-2026-66491, Joomla üçün Phoca Commander komponentində (1.0.0-dan 6.1.3-ə qədər versiyalarda) aşkarlanan kritik bir zəiflikdir. Bu qüsur, `getSource` funksiyasındakı yol məhdudiyyətinin düzgün tətbiq olunmaması səbəbindən uzaqdan autentifikasiya olunmamış hücumçulara serverdə ixtiyari fayl oxumaq imkanı verir. Bu komponenti istifadə edən bütün Joomla saytlarını dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: phoca.cz
FAQ2
Which Joomla component is affected by CVE-2026-66491?
This vulnerability affects the Phoca Commander component for Joomla.
Is authentication required for an attacker to exploit CVE-2026-66491?
No, this flaw can be exploited by unauthenticated remote attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.