CVE-2026-66915Patch

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-11); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-08-10: 1Mentions · 2026-08-11: 3Mentions · 2026-08-24: 1Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-08-11: 3Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-24: 108-1008-1108-24
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-101
Patch1
2026-08-113
Patch3
2026-08-241
Disclosure1
Full discourse5 posts
  • Modat@modat_magnify
    Disclosure

    ⚠️ Joomla / Fabrik – Unauthenticated RCE in the Calc Element (CVSS 10.0) A critical code injection vulnerability (CVE-2026-66915) in Fabrik, the widely used application and form builder extension for Joomla, allows unauthenticated attackers to execute arbitrary code on the server via the calc element's AJAX recalculation endpoint. The calc element evaluates a site-builder PHP expression to work out a field's value, and because the recalculation feature requires no login, attackers can reach that evaluation directly and achieve full server compromise. Affected: Fabrik 1.0.0 through 4.6.8, across both the Fabrik 3.x line (Joomla 3) and 4.x line (Joomla 4/5). Mitigation: Update Fabrik to 4.7.2, the current release. 4.6.7 and 4.6.8 remain vulnerable. Joomla's update feed may not offer the fixed build on sites below Joomla 5.4, so verify the installed version manually rather than trusting an "up to date" report. Modat Magnify Query: (fingerprints.technologies.​name="Joomla" or http.body~"Joomla! - Open Source Content Management") and fingerprints.tags!="Honeypot" The platform: https://magnify.modat.io/ #threatintel #vulnerability #CVE202666915 #Joomla #Fabrik #RCE #infosec #Critical #ModatMagnify

    Post summary

    The post discloses a new unauthenticated RCE vulnerability (CVE‑2026‑66915) in Fabrik for Joomla, specifies technical details, and provides a patch recommendation.

    01020358
    1.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical unauthenticated #RCE vulnerability in #Joomla extension #Fabrik. CVE-2026-66915 CVSS: 10.0. Update to version 4.6.8 (10 Aug 2026) as the previous fix 4.6.7 (9 Aug 2026) is incomplete. #Patch #Patch #Patch

    Post summary

    The message warns of an unauthenticated RCE in the Joomla Fabrik extension (CVE‑2026‑66915, CVSS 10.0) and urges users to upgrade to version 4.6.8, as the earlier 4.6.7 patch was incomplete.

    01000314
    7.2K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🧩 Joomla's Fabrik extension: unauthenticated RCE via the ajax_calc feature in the calc plugin. No auth needed. CVSS 10. Update to 4.6.7 now. CVE-2026-66915 #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-66915?utm_campaign=x https://t.co/AOJHSMbyQI

    Post summary

    Joomla's Fabrik extension allows unauthenticated RCE (CVSS 10); a patch (v4.6.7) is available, but no PoC or active exploitation is reported.

    0000097
    877 followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    Fabrik for Joomla 4.6.7 fixes an unauthenticated RCE in the calc element. CVE-2026-66915, CVSS 10.0. Every version up to 4.6.6 is affected. Update now. https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/?utm_source=twitter&utm_medium=social #Joomla https://t.co/k2g4gGnl68

    Post summary

    Fabrik for Joomla is vulnerable to the unauthenticated RCE CVE‑2026‑66915 (CVSS 10.0); version 4.6.7 provides a fix, and users are urged to update.

    00000114
    2.6K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Patch

    Fabrik for Joomla 4.6.7 fixes an unauthenticated RCE in the calc element. CVE-2026-66915, CVSS 10.0. Every version up to 4.6.6 is affected. Update now. https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/?utm_source=twitter&utm_medium=social #Joomla https://t.co/7k63c3b1KL

    Post summary

    A critical RCE (CVE‑2026‑66915) in Fabrik for Joomla up to 4.6.6 has been patched in version 4.6.7; users are advised to apply the update immediately.

    00000126
    2.6K followersView on X

Explore more