What is CVE-2026-67283?
CVE-2026-67283 is an improper ACL implementation in the Cotton Cloud component of the tabaoca.org Joomla extension, allowing unauthenticated users to perform file operations (read, delete, overwrite, reassign permissions) on managed files. This affects versions before 2.0.2. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-67283, Joomla üçün tabaoca.org genişlənməsinin Cotton Cloud komponentində düzgün icra olunmayan ACL (Access Control List) səbəbindən autentifikasiya olunmamış istifadəçilərə fayl əməliyyatları (oxuma, silmə, üzərinə yazma, icazələri dəyişmə) aparmağa imkan verir. Bu boşluq 2.0.2-dən əvvəlki versiyalara təsir edir. Genişlənməni dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which component of the tabaoca.org Joomla extension was CVE-2026-67283 discovered?
This vulnerability occurs in the Cotton Cloud component due to improper ACL implementation.
What file operations can an unauthenticated attacker perform by exploiting this vulnerability?
An attacker can perform read, delete, overwrite, and reassign permissions operations on managed files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.