CVE-2026-66915 CRITICAL

CVE-2026-66915: Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.7

Vendor Fabrikar.com
Product Fabrik extension for Joomla
Weakness CWE-94 · Code injection
Published August 10, 2026
Last update August 10, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

Explanation of Vulnerability in Simple Terms

02Summary

The Fabrik extension for Joomla contains a code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code on the site without user interaction. The vulnerability exists in versions 1.0.0-4.6.6 and earlier. An attacker can exploit this remotely over the network to gain full control of the Joomla installation.

What an attacker can do

03Attacker Capabilities

Run arbitrary PHP code on the site and take complete control of the Joomla installation.

Potential impact on your site

04Site Impact

Complete compromise of the Joomla site, including data theft, malware injection, and loss of site control.

Conditions required to exploit

05Prerequisites

None. The vulnerability can be exploited remotely without authentication or user interaction.

Key dates

06Disclosure timeline

August 10, 2026 CVE published

Related vulnerabilities

08Related CVE