What is CVE-2026-67282?
This critical vulnerability (CVE-2026-67282) allows unauthenticated remote code execution (RCE) in Joomla's Fabrik extension versions prior to 4.6.8. An attacker can execute arbitrary code by leveraging the frontend listfilter model. Immediate update to Fabrik version 4.6.8 or later is strongly recommended.
Azərbaycanca: Bu kritik boşluq (CVE-2026-67282) Joomla-nın Fabrik genişlənməsinin 4.6.8-dən əvvəlki versiyalarında autentifikasiya olunmadan uzaqdan kod icrasına (unauthenticated RCE) imkan verir. Təcavüzkar frontend listfilter modelindən istifadə edərək ixtiyari kod icra edə bilər. Dərhal Fabrik-i ən azı 4.6.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: fabrikar.com
FAQ2
Is authentication required to exploit CVE-2026-67282?
No, this critical vulnerability allows unauthenticated remote code execution (RCE).
Which Joomla component does CVE-2026-67282 affect?
This vulnerability affects the Fabrik extension of Joomla.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.