CVE-2026-76606
CVE-2026-76606 is a critical-severity vulnerability with a CVSS 4.0 base score of 10.0. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Critical (CVSS 4.0 base score 10.0)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Published:
- Last modified:
Description
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
Frequently asked questions
- What is CVE-2026-76606?
- Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- How severe is CVE-2026-76606?
- CVE-2026-76606 has a CVSS 4.0 base score of 10.0, rated critical severity.
- Is CVE-2026-76606 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-76606?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-76606 published?
- CVE-2026-76606 was published on 2026-08-22.
References
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- CVE-2026-48282 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted…