CVE-2026-102427 — Joomla Cck
CRITICALCVE-2026-102427 is a critical-severity (CVSS 10) Unrestricted File Upload vulnerability in ordasoft joomla cck. A fix is available — see the affected versions and patch details below.
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing…
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-102427 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 381,682 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Description
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.
Affected Products
joomla cckordasoftDetection & mitigation playbook
Vendor / applianceDetect
Inventory every ordasoft joomla cck deployment and check each version against the affected-products list above.
Fix
Apply the ordasoft joomla cck security patch or hotfix for CVE-2026-102427 on the affected version, following the vendor advisory for your exact build.
Workarounds
Treat uploaded files as untrusted until proven otherwise: validate the actual content type rather than the supplied extension, store uploads outside the web root on a volume mounted without execute permission, and rename them to server-generated identifiers so an attacker cannot choose the path a request will later resolve. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
Frequently Asked Questions
Is CVE-2026-102427 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.