Joomla CCK unauthenticated RCE (CVE-2026-102427) [PoC]
CVE-2026-102427
CVE-2026-102427: OrdaSoft Joomla CCK before 8.3.16 allows unauthenticated attackers to upload and execute PHP (CVSS 10.0). Update to 8.3.16 now.
Exploitation confirmed - public proof-of-concept - CVE-2026-102427 is a critical unauthenticated remote code execution vulnerability in OrdaSoft Joomla CCK versions before 8.3.16 that lets any remote attacker upload and execute arbitrary PHP on the server. No authentication, account, or user interaction is required; the vendor has released 8.3.16 and sites should update immediately.
Overview
OrdaSoft Joomla CCK is a content construction kit component for Joomla that extends the platform with custom content types and upload handling. The flaw lives in the component’s frontend uploader at site/uploader.php, which is reachable through normal frontend routing with the task=getContent parameter. That dispatch path contains no authentication check and no ACL enforcement at any point, so anonymous visitors reach the upload handler directly.
The handler does validate the content of an uploaded file with a real magic-byte MIME check. The weakness is in what happens after: the extension allow-list that would restrict saved filenames was written in the source code but commented out. The saved file keeps whatever extension the attacker supplies, and it is written to a path directly under the Joomla web root that the PHP handler executes.
Impact
An attacker sends an image/PHP polyglot: a file whose leading bytes satisfy the magic-byte MIME check, with PHP source appended after the image header. The content check passes, the filename keeps a .php extension, and the file lands in an executable web directory. The result is unauthenticated remote code execution under the web server’s user context.
From there, an attacker can read configuration files including database credentials in configuration.php, pivot to the underlying database, plant persistent backdoors, and use the host as a launch point for lateral movement. Because the vulnerable path requires no credentials, the attack surface is the entire public internet - any scanner that identifies the component can attempt exploitation. CVSS scores this 10.0: network attack vector, low complexity, no privileges, no user interaction.
Remediation and Mitigation
- Update OrdaSoft Joomla CCK to version 8.3.16 or later. This is the only complete fix.
- If you cannot patch immediately, block requests containing
task=getContentat the WAF or reverse proxy, and deny execution of PHP files in the component’s upload directory. - Audit the upload directory and the Joomla web root for unexpected
.phpfiles, especially ones starting with image magic bytes - delete any found. - Rotate Joomla
configuration.phpsecrets, database credentials, and any API keys stored on affected hosts, and review server logs for POST requests tosite/uploader.php. - Check filesystem timestamps around any suspicious uploads to scope potential compromise.
Data breach reports and active incident disclosures are tracked at breach reports, and ongoing coverage is available at security news.
Security Insight
This bug is a textbook example of dead code becoming a live vulnerability: the extension allow-list existed, was correct, and was left commented out in a shipped release. It also shows how a single missing ACL check in a frontend dispatch chain collapses every downstream control - the MIME validation was legitimate and still useless, because content checks cannot constrain a filename the attacker chooses. Components that combine public upload endpoints with web-root write paths deserve default-deny treatment from Joomla extension developers, not optional allow-lists that can be silently disabled.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| murrez/CVE-2026-102427 CVE-2026-102427 is an unauthenticated remote code execution flaw in OrdaSoft Joomla Content Construction Kit (OS CCK) — Joomla component com_os_cck. | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions u...
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_ac...
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE....