{"id":"CVE-2026-73327","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73327","summary":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory…","details":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.","published":"2026-08-12T18:18:15.480","modified":"2026-08-12T18:18:15.480","cvss":{"score":7.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/joomla/joomla-cms/commit/9678a171d37e1e10ca75c9124bdafe20fe14fa5b","label":"joomla/joomla-cms@9678a17"},"references":[{"type":"WEB","url":"https://github.com/joomla/joomla-cms"},{"type":"WEB","url":"https://github.com/joomla/joomla-cms/commit/9678a171d37e1e10ca75c9124bdafe20fe14fa5b"},{"type":"WEB","url":"https://github.com/joomla/joomla-cms/pull/48057"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/joomla-zip-slip-path-traversal-via-com-joomlaupdate-extract-php"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T18:18:15.480"}}