What is CVE-2026-66492?
This vulnerability is a Path Traversal flaw in the Joomla Phoca Commander extension caused by improper path limitation in its file upload action. It affects Phoca Commander versions 1.0.0 through 6.1.3, allowing a remote attacker to write files to unauthorized server locations. Users should immediately upgrade the extension to the latest patched version.
Azərbaycanca: Bu zəiflik Joomla Phoca Commander əlavəsindəki fayl yükləmə funksiyasında yol məhdudiyyətinin düzgün tətbiq edilməməsi səbəbindən yaranan Path Traversal boşluğudur. Phoca Commander-in 1.0.0-dən 6.1.3-ə qədər olan versiyalarını təsirləyir və uzaqdan hücum edən şəxsə serverdə icazəsiz fayl yazmağa imkan verir. İstifadəçilər dərhal əlavəni ən son təhlükəsizlik yeniləməsi olan versiyaya qaldırmalıdır.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: phoca.cz
FAQ2
Which Joomla extension is affected by CVE-2026-66492?
This vulnerability affects the Joomla Phoca Commander extension.
What should users do to protect against CVE-2026-66492?
Users should immediately upgrade the extension to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.