CRITICAL 10.0 CVE-2026-102427 Published 30 Sept 2026

OrdaSoft Joomla CCK Unauthenticated Remote Code Execution Vulnerability

Worried this affects your website?

OrdaSoft Joomla CCK versions before 8.3.16 contain an unauthenticated remote code execution vulnerability. The component's site/uploader.php is reachable through normal frontend routing via task=getContent, with no authentication or ACL check in the dispatch chain.

The upload handler performs a real magic-byte MIME check on file content, but the extension allow-list that would restrict saved file extensions is commented out in the source. The saved extension is taken directly from the attacker-supplied filename without validation, and the file is written to a path under the Joomla web root that the PHP handler executes.

  • Affected: OrdaSoft Joomla CCK before 8.3.16
  • Attack vector: unauthenticated frontend request to task=getContent
  • Impact: arbitrary PHP file upload and remote code execution

An image/PHP polyglot—a file whose header bytes satisfy the MIME check with PHP source appended—can pass the content check while carrying a .php extension of the attacker's choosing.

Reference: CVE-2026-102427 on NVD

← Back to Security News