What is CVE-2026-67284?
This vulnerability exists in the 'tabaoca.org' extension for Joomla (Cotton Cloud component). Due to an improper ACL implementation in versions below 2.0.3, authenticated users could perform file operations such as reading, deleting, overwriting, and re-assigning permissions on files owned by other users. Updating the Cotton Cloud component to version 2.0.3 or later is recommended to fix the issue.
Azərbaycanca: Bu zəiflik Joomla üçün 'tabaoca.org' uzantısında (`Cotton Cloud` komponenti) aşkarlanıb. 2.0.3-dən əvvəlki versiyalarda düzgün olmayan ACL tətbiqi autentifikasiya olunmuş istifadəçilərə başqa istifadəçilərə məxsus fayllar üzərində oxuma, silmə, üzərinə yazma və icazələri dəyişmə kimi əməliyyatlar aparmağa imkan verir. Bu problemi aradan qaldırmaq üçün 'Cotton Cloud' komponentini ən azı 2.0.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What component is affected by CVE-2026-67284 and how can I fix it?
This vulnerability affects the Cotton Cloud component of the 'tabaoca.org' extension for Joomla. To fix the issue, it is recommended to update the component to version 2.0.3 or later.
What operations could an authenticated user perform by exploiting CVE-2026-67284?
Due to the improper ACL implementation, an authenticated user could perform file operations such as reading, deleting, overwriting, and re-assigning permissions on files owned by other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.