CVE-2026-76604

CVE-2026-76604 is a critical-severity vulnerability with a CVSS 4.0 base score of 10.0. The underlying weakness is classified as CWE-94.

Key facts

Description

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.

Frequently asked questions

What is CVE-2026-76604?
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.
How severe is CVE-2026-76604?
CVE-2026-76604 has a CVSS 4.0 base score of 10.0, rated critical severity.
Is CVE-2026-76604 being actively exploited?
It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
How do I fix CVE-2026-76604?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
When was CVE-2026-76604 published?
CVE-2026-76604 was published on 2026-08-22.

References

Other CWE-94 (Code Injection) vulnerabilities

Browse all CWE-94 (Code Injection) vulnerabilities →