CVE-2026-84048

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    JoomGallery TUS upload: no login, write into temp, steal someone else’s in-flight file!!! CVE-2026-84048: JoomGallery 4.0.0–4.4.1 accepted unauthenticated TUS uploads. Filename/extension are not attacker-chosen, so this is not a clean webshell drop. Any visitor can still plant files in temp and read/delete another upload mid-flight!! Real patch is 4.4.2 https://mysites.guru/blog/joomgallery-unauthenticated-file-upload/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #AppSec #FileUpload

    00021128
    924 followersView on X

Explore more