CVE-2026-75115Disclosure

LOWCVSS 7.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-21: 2Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 208-21
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • YOOtheme@yootheme
    Patch

    🚨 Critical security update for YOOtheme We fixed 2 vulnerabilities: CVE-2026-75115: Arbitrary file read (contributor-level) CVE-2026-76613: SQL injection (contributor-level) Update YOOtheme immediately to 5.0.41 if untrusted users have permission to create articles.

    Post summary

    YOOtheme issued a critical update (v5.0.41) to fix CVE‑2026‑75115 and CVE‑2026‑76613; users are urged to update immediately.

    13050574
    13.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75115 Authenticated Arbitrary File Read in YOOtheme Pro 2.3.0-5.0.40 via Glob Pattern Attack https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75115

    Post summary

    Announces CVE-2026-75115, an authenticated arbitrary file read vulnerability in YOOtheme Pro 2.3.0‑5.0.40, exploitable through a glob pattern attack.

    00000130
    4.1K followersView on X

Explore more