rootpwn

critical · CVSS v3 8.8 · CVSS v4 9.4

CVE-2026-88857

The OrdaSoft Joomla Gallery extension allows authenticated privileged users to upload arbitrary PHP files via the watermark function, storin

Overview

The OrdaSoft Joomla Gallery extension allows authenticated privileged users to upload arbitrary PHP files via the watermark function, storing them in a web-accessible directory without sanitization, enabling remote code execution. This flaw affects all Joomla sites using the extension before version 6.2.7.

Description

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.

Impact

Confidentiality: attackers can read site files. Integrity: attackers can modify or delete content. Availability: attackers can disrupt site operation. Impacted parties: site administrators, users, and any organization hosting the vulnerable extension.

Remediation

Upgrade OrdaSoft Joomla Gallery to version 6.2.7 or later. If upgrade not possible, disable the watermark upload feature or restrict file types to images only, and ensure the upload directory is not web-accessible. Apply Joomla core security updates and enforce least privilege for core.manage users.

Risk context

Severity is critical with CVSS 8.8/9.4. No EPSS data. Immediate attention required to prevent exploitation.

Affected products

  • OrdaSoft Joomla Gallery
  • Joomla CMS

Scores

Severity
critical
CVSS v2
6.5
CVSS v3
8.8
CVSS v4
9.4
EPSS

Joomla OrdaSoft Remote Code Execution Privilege Escalation File Upload Critical Web Application

← All CVEs