CVE-2026-75949Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-19: 1Mentions · 2026-08-23: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-23: 108-1908-23
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-231
Patch1
Full discourse2 posts
  • SecAlerts@SecAlertsCo
    Patch

    📁 Joomla J-BusinessDirectory &lt; 6.2.3: client-controlled _path_type enables arbitrary file upload/deletion via path traversal. No auth required. CVSS 10. CVE-2026-75949 — upgrade now. #cybersecurity #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-75949?utm_campaign=x https://t.co/zHjAMM1WcU

    Post summary

    A Joomla J‑BusinessDirectory vulnerability (CVE‑2026‑75949) allows unauthenticated attackers to upload or delete files via path traversal with a CVSS score of 10, and users are urged to upgrade immediately.

    0000089
    878 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - J-BusinessDirectory Joomla Arbitrary Upload/Delete via Path Traversal (CVE-2026-75949) J-BusinessDirectory for Joomla exposes upload/remove actions that accept a client-controlled root path; missing path containment enables traversal to write/delete arbitrary files. Weak extension validation + no CSRF lets attackers upload webshells or delete site files, leading to full site compromise. 👉Affected: J-BusinessDirectory extension for Joomla (all versions)

    Post summary

    The post announces a critical path‑traversal flaw in J-BusinessDirectory for Joomla that allows attackers to upload web shells or delete files, potentially compromising entire sites.

    0000067
    292 followersView on X

Explore more