CVE-2026-84048

Summary

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.

Affected Software

VendorProductVersion RangeStatus
joomgalleryfriends.netJoomGallery extension for Joomla4.0.0-4.4.1affected

Weaknesses

  • CWE-284: CWE-284 - Improper Access Control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References