CVE-2026-94131

LOWCVSS 8.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-27)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-26: 1Mentions · 2026-09-27: 209-2609-27
Referenced assets3 URLs
Full discourse3 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 Joomla eklentilerinde kritik güvenlik açıkları! Joomla ekosisteminde çok sayıda önemli / kritik güvenlik açığı yayınlandı. CVE-2026-97163 — CVSS 10.0 Critical : UP Universal Plugin — Uzaktan kod yükleme / çalıştırma CVE-2026-97160 — CVSS 9.4 Critical : UP Universal Plugin — PHP command injection CVE-2026-97161 — CVSS 9.2 Critical : UP Universal Plugin — Path Traversal / yetkisiz dosya erişimi CVE-2026-94132 — CVSS 9.5 Critical : AcyMailing Enterprise < 11.1.0 — RCE CVE-2026-94131 — CVSS 8.3 High : AcyMailing Enterprise < 11.1.0 — Yetkisiz dosya silme 📌 UP Universal Plugin: Etkilenen sürümler için UP 6.1.0 / eski Joomla serileri için 5.2.1 sürümüne güncellenmesi öneriliyor. 📌 AcyMailing Enterprise: 11.1.0 veya üzeri sürüme güncellenmeli. ⚠️ Sunucularınızdaki Joomla eklentilerini ve sürümlerini kontrol edin.

    00073473
    2.4K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru

    AcyMailing 11.1.0 filed two security fixes under Bug fixes. Now they have CVEs: CVE-2026-94132, a mailbox file write rated 9.5 Critical, and CVE-2026-94131, a file deletion. https://mysites.guru/blog/acymailing-11-1-0-security-release/?utm_source=twitter&utm_medium=social https://t.co/CRiZaafifn

    1000027
    2.6K followersView on X
  • CVE@CVEnew

    CVE-2026-94131 Joomla Extension - https://acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension &lt; 11.1.0 - A subscriber could store a path in a file-ty… https://www.cve.org/CVERecord?id=CVE-2026-94131

    00000882
    58.1K followersView on X

Explore more