What is CVE-2026-66493?
This is a Path Traversal vulnerability in the Phoca Commander extension (1.0.0-6.1.3) for Joomla. Improper limitation of paths for delete, copy, and move actions could allow remote code execution. Users are advised to update the extension immediately or temporarily disable it.
Azərbaycanca: Bu zəiflik Joomla üçün Phoca Commander (1.0.0-6.1.3) əlavəsində aşkarlanmış Path Traversal boşluğudur. Silmə, kopyalama və yerdəyişmə əməliyyatlarında yol məhdudiyyətlərinin düzgün tətbiq edilməməsi səbəbindən uzaqdan kod icrası riski yarana bilər. İstifadəçilərə dərhal əlavəni ən son versiyaya yeniləmək və ya müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: phoca.cz
FAQ2
In which Joomla extension was CVE-2026-66493 discovered?
This vulnerability was discovered in the Phoca Commander extension for Joomla, affecting versions 1.0.0 through 6.1.3.
What is the main risk if CVE-2026-66493 is exploited?
Due to the Path Traversal vulnerability, improper limitation of paths for delete, copy, and move actions could allow remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.