What is CVE-2026-66915?
This vulnerability exists in Fabrik extension for Joomla versions prior to 4.6.9. An unauthenticated attacker can achieve Remote Code Execution via the 'ajax_calc' feature of the 'calc' plugin. System administrators should immediately update the extension to the latest 4.6.9 version.
Azərbaycanca: Bu boşluq Joomla üçün Fabrik genişlənməsinin 4.6.9-dan əvvəlki versiyalarında aşkarlanıb. Hesabı olmayan hücumçu 'calc' plagininin 'ajax_calc' funksiyası vasitəsilə uzaqdan kod icrası (Remote Code Execution) həyata keçirə bilər. Sistem administratorları dərhal genişlənməni ən son 4.6.9 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: fabrikar.com
FAQ2
Which component does CVE-2026-66915 affect?
This vulnerability affects the Fabrik extension for Joomla versions prior to 4.6.9.
What action should be taken to mitigate the risk associated with CVE-2026-66915?
System administrators should immediately update the Fabrik extension to version 4.6.9.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.