discovered 03 Aug 2026
CVE-2026-57827
→ View on GitHubCVE-2026-57827 is a high-severity vulnerability within the RSFiles! component for Joomla, allowing unauthenticated arbitrary file uploads due to a split-controller design flaw. The vulnerability permits attackers to bypass critical security checks and directly write malicious files to the server, resulting in remote code execution without any authentication or CSRF protections. Notably, the exploit allows attackers to upload any file type and store it in a default web-accessible directory, significantly compromising the security of affected Joomla installations.