Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
CRITICAL severity

CVE-2026-102427 — Joomla Cck

CRITICAL

CVE-2026-102427 is a critical-severity (CVSS 10) Unrestricted File Upload vulnerability in ordasoft joomla cck. A fix is available — see the affected versions and patch details below.

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing…

Published
Sep 30, 2026
Updated
Oct 1, 2026
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 1, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
0.8%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs56th percentile — riskier than 56% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-102427 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 381,682 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Description

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.

Affected Products

1 product · 1 configurations
Application
joomla cckordasoft
≥ 1.0.0 && < 8.3.16
range

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every ordasoft joomla cck deployment and check each version against the affected-products list above.

  2. Fix

    Apply the ordasoft joomla cck security patch or hotfix for CVE-2026-102427 on the affected version, following the vendor advisory for your exact build.

  3. Workarounds

    Treat uploaded files as untrusted until proven otherwise: validate the actual content type rather than the supplied extension, store uploads outside the web root on a volume mounted without execute permission, and rename them to server-generated identifiers so an attacker cannot choose the path a request will later resolve. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Frequently Asked Questions

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and t
O3 Security · Runtime Protection

Is CVE-2026-102427 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2026-102427: Joomla Cck (Critical 10) | O3 Security