CVE-2026-102427(ordasoft / joomla_cck)

LOWCVSS 10.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomla_cck

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-10-01)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
joomla_cck

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-30: 1Mentions · 2026-10-01: 309-3010-01
Referenced assets7 URLs
Full discourse4 posts
  • Dev 101x@Devcop101

    🚨 Critical RCE in Joomla CCK (&lt;8.3.16) ​CVE-2026-102427 allows unauthenticated arbitrary code execution via site/uploader.php https://devcop95.github.io/cYHBernews giving attackers full server takeover with zero login required. ​Update immediately! ​#CyberSecurity #InfoSec #Joomla #RCE https://t.co/DF5AMtdIq8

    0101136
    54 followersView on X
  • mürrez@murrezsec

    🚨 CVE-2026-102427 A new security vulnerability has been documented. Details &amp; PoC: 🔗 https://pocbit.org/pocs/cve-2026-102427 #CVE #CyberSecurity #InfoSec #AppSec #Vulnerability #SecurityResearch

    0002167
    626 followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-102427 PT ID: PT-2026-103328 Vendor: Joomla / http://ordasoft.com Product: OrdaSoft Joomla CCK Description: Joomla Extension - http://ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing. References: • https://dbu.gs/vulnerability/PT-2026-103328 • https://github.com/murrez/cve-2026-102427

    0000097
    3.6K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru

    CVE-2026-102427: OS CCK for Joomla let anyone upload and run PHP with no login. CVSS 10.0. Fixed in 8.3.16, but OrdaSoft's updater still offers 8.3.14, so install it by hand. https://mysites.guru/blog/ordasoft-os-cck-sql-injection/?utm_source=twitter&utm_medium=social https://t.co/QERDWKgfIa

    0000030
    2.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appordasoftjoomla_cck-joomla\!-

Explore more