Summary
CVE-2026-76607 is a missing access-control-list (ACL) check in the download element of the Fabrik extension for Joomla, allowing unauthorized access to files served through that element. The flaw affects all Fabrik releases from 1.0.0 through 4.7.3 and has been assigned a CVSS v4.0 base score of 10.0 (Critical) by the Joomla CNA. The issue was reported by Phil Taylor of mySites.guru.
Technical details
- Root cause: The Fabrik download element does not perform the expected ACL/permission check before serving a file, per CWE-284 (Improper Access Control).
- Trigger conditions: A request to the download element’s file-serving functionality on a site running an affected Fabrik version.
- Attack vector: Network-based; the published vector string indicates no privileges and no user interaction are required (
PR:N/UI:N). - Impact: High impact to confidentiality, integrity, and availability, with the CVSS v4.0 vector also reflecting high subsequent-system impact (
SC:H/SI:H/SA:H), consistent with unauthorized retrieval of files that should be access-restricted.
Affected software
- Fabrik extension for Joomla (fabrikar.com), versions 1.0.0 through 4.7.3
- Versions 4.7.3 and later are not affected per the CVE record
Severity
- CVSS v4.0 Base Score: 10.0 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Mitigation and recommended actions
- Immediate: Upgrade Fabrik to a version later than 4.7.3 (the version at which the CVE record marks the product as unaffected). Obtain the update directly from fabrikar.com.
- If unable to patch immediately: Restrict or disable access to the Fabrik download element’s front-end endpoint until the upgrade can be applied, and audit logs for unexpected file-download requests.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/media/com_fabrik/,/components/com_fabrik/

