Summary
CVE-2026-102428 is a critical, unauthenticated SQL injection vulnerability in the OrdaSoft Joomla CCK extension (component com_os_cck) for Joomla. The flaw stems from improper validation of a user-supplied "order column" parameter used in record sorting, allowing attackers to inject arbitrary SQL without any authentication. The issue is rated 9.3 (Critical) and is remotely exploitable over the network.
Technical details
- Root cause: The parameter controlling the sort/order column for CCK records is accepted from user input and passed into a SQL query without proper sanitization or parameterization (CWE-89).
- Trigger conditions: An attacker sends a crafted request to a Joomla site running the vulnerable OrdaSoft CCK component, manipulating the order-column parameter to inject SQL syntax.
- Attack vector: Network-based; no authentication and no user interaction required.
- Impact: Successful exploitation can allow reading, modifying, or exfiltrating database contents, and may lead to full compromise of data confidentiality, integrity, and availability depending on database permissions and site configuration.
Affected software
- OrdaSoft Joomla CCK extension (
com_os_cck), versions 1.0.0 through 8.3.15 - Fixed in version 8.3.16
Severity
- CVSS v4.0 Base Score: 9.3 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade the OrdaSoft Joomla CCK extension to version 8.3.16 or later, where the order-column input is properly validated.
- If immediate patching is not possible:
- Restrict or disable public access to the affected CCK component’s front-end endpoints until the update can be applied.
- Deploy a web application firewall (WAF) rule to detect and block SQL injection patterns targeting CCK sorting/order parameters.
- Monitor web server and database logs for anomalous queries or errors referencing the CCK component.
- Review database accounts used by Joomla/CCK for least-privilege access to limit the impact of any successful injection.

