
⚠️ Joomla / Fabrik – Unauthenticated RCE in the Calc Element (CVSS 10.0) A critical code injection vulnerability (CVE-2026-66915) in Fabrik, the widely used application and form builder extension for Joomla, allows unauthenticated attackers to execute arbitrary code on the server via the calc element's AJAX recalculation endpoint. The calc element evaluates a site-builder PHP expression to work out a field's value, and because the recalculation feature requires no login, attackers can reach that evaluation directly and achieve full server compromise. Affected: Fabrik 1.0.0 through 4.6.8, across both the Fabrik 3.x line (Joomla 3) and 4.x line (Joomla 4/5). Mitigation: Update Fabrik to 4.7.2, the current release. 4.6.7 and 4.6.8 remain vulnerable. Joomla's update feed may not offer the fixed build on sites below Joomla 5.4, so verify the installed version manually rather than trusting an "up to date" report. Modat Magnify Query: (fingerprints.technologies.name="Joomla" or http.body~"Joomla! - Open Source Content Management") and fingerprints.tags!="Honeypot" The platform: https://magnify.modat.io/ #threatintel #vulnerability #CVE202666915 #Joomla #Fabrik #RCE #infosec #Critical #ModatMagnify
Post summary
The post discloses a new unauthenticated RCE vulnerability (CVE‑2026‑66915) in Fabrik for Joomla, specifies technical details, and provides a patch recommendation.



