CVE-2026-76570

LOWCVSS 10.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 4 mentions (2026-09-30); latest day: 4
  • 8 total mentions across 2 days

Deep dive

Activity timeline8 mentions / 2d
01234Mentions · 2026-09-30: 4Mentions · 2026-10-01: 409-3010-01
Referenced assets5 URLs
Full discourse8 posts
  • ʞʞıdɐɔoɥƆ@Chocapikk_

    CVE-2026-76570: unauth SQLi in JCTables (JoomCode's Joomla data-table), read/write to RCE. No auth, no CSRF, broken escaping. One request leaks the admin creds, then reset the password, log in, and drop a webshell. Affected through 1.10.31.2, fixed 1.21.1. https://www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rce

    3802491.2K
    4.1K followersView on X
  • Ryx@PadhiyarRushi

    JCTables front-end CRUD has no token and no login. SQL read and write, then a self-deleting webshell!! CVE-2026-76570: JoomCode JCTables through 1.10.31.2. The controller treats the value as already escaped, then interpolates it. VulnCheck (Chocapikk) showed the chain yesterday: blind boolean for the prefix, borrow an admin, plant a plugin whose postflight writes /images/*.php and deletes itself. Fixed in 1.21.1. Go-exploit module and a Python checker are both public! https://www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rce #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #SQLi #RCE

    10010135
    940 followersView on X
  • Ryx@PadhiyarRushi

    Working PoC: https://github.com/murrez/CVE-2026-76570

    0001029
    940 followersView on X
  • mürrez@murrezsec

    🚨 CVE-2026-76570 — Joomla JCTables 1.21.1 Unauthenticated SQL Injection affecting read & write queries via the front-end CRUD API. 🔗 https://pocbit.org/pocs/cve-2026-76570 #CVE #Joomla #SQLi #SQLInjection #CyberSecurity #InfoSec #AppSec #Vulnerability

    0001075
    626 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Joomla JCTables Unauth SQLi via Front-end CRUD API (CVE-2026-76570) Joomla JCTables extension front-end CRUD API controller skips Joomla token validation and auth checks, then concatenates attacker-supplied table/column/value params directly into SQL queries. Unauthenticated attackers can SQLi to read/modify DB data and potentially create admin users. Admin-only back-end actions are not affected. 👉Affected: Joomla JCTables extension (versions unknown)

    0000030
    309 followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru

    CVE-2026-76570: JCTables for Joomla let anyone read and rewrite the site's database, no login needed. Scored 10.0 Critical, fixed in 1.21.1. Update now: https://mysites.guru/blog/jctables-joomla-sql-injection/?utm_source=twitter&utm_medium=social https://t.co/rgCtppSVei

    0000027
    2.6K followersView on X
  • Severity Daily@severitydaily

    Joomla (@joomla) scored a JCTables SQL injection 10.0 and its CVE names 1.21.1 as the affected version. 1.21.1 is the fix. No exploitation reported, but the exploit chain is public as of today. https://severitydaily.com/joomla-jctables-cve-2026-76570-attacked-ssvc-none-version-inversion/

    0000032
    28 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-76570 Vendor → Unknown Severity → Critical — CVSS 10.0 Product → Unknown Date → 2026-09-30 A critical vulnerability (SQL Injection) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000068
    429 followersView on X

Explore more