Critical 10.0

Joomla CCK unauthenticated RCE (CVE-2026-102427) [PoC]

CVE-2026-102427

By Yazoul AI · automated

CVE-2026-102427: OrdaSoft Joomla CCK before 8.3.16 allows unauthenticated attackers to upload and execute PHP (CVSS 10.0). Update to 8.3.16 now.

Exploitation confirmed - public proof-of-concept - CVE-2026-102427 is a critical unauthenticated remote code execution vulnerability in OrdaSoft Joomla CCK versions before 8.3.16 that lets any remote attacker upload and execute arbitrary PHP on the server. No authentication, account, or user interaction is required; the vendor has released 8.3.16 and sites should update immediately.

Overview

OrdaSoft Joomla CCK is a content construction kit component for Joomla that extends the platform with custom content types and upload handling. The flaw lives in the component’s frontend uploader at site/uploader.php, which is reachable through normal frontend routing with the task=getContent parameter. That dispatch path contains no authentication check and no ACL enforcement at any point, so anonymous visitors reach the upload handler directly.

The handler does validate the content of an uploaded file with a real magic-byte MIME check. The weakness is in what happens after: the extension allow-list that would restrict saved filenames was written in the source code but commented out. The saved file keeps whatever extension the attacker supplies, and it is written to a path directly under the Joomla web root that the PHP handler executes.

Impact

An attacker sends an image/PHP polyglot: a file whose leading bytes satisfy the magic-byte MIME check, with PHP source appended after the image header. The content check passes, the filename keeps a .php extension, and the file lands in an executable web directory. The result is unauthenticated remote code execution under the web server’s user context.

From there, an attacker can read configuration files including database credentials in configuration.php, pivot to the underlying database, plant persistent backdoors, and use the host as a launch point for lateral movement. Because the vulnerable path requires no credentials, the attack surface is the entire public internet - any scanner that identifies the component can attempt exploitation. CVSS scores this 10.0: network attack vector, low complexity, no privileges, no user interaction.

Remediation and Mitigation

  • Update OrdaSoft Joomla CCK to version 8.3.16 or later. This is the only complete fix.
  • If you cannot patch immediately, block requests containing task=getContent at the WAF or reverse proxy, and deny execution of PHP files in the component’s upload directory.
  • Audit the upload directory and the Joomla web root for unexpected .php files, especially ones starting with image magic bytes - delete any found.
  • Rotate Joomla configuration.php secrets, database credentials, and any API keys stored on affected hosts, and review server logs for POST requests to site/uploader.php.
  • Check filesystem timestamps around any suspicious uploads to scope potential compromise.

Data breach reports and active incident disclosures are tracked at breach reports, and ongoing coverage is available at security news.

Security Insight

This bug is a textbook example of dead code becoming a live vulnerability: the extension allow-list existed, was correct, and was left commented out in a shipped release. It also shows how a single missing ACL check in a frontend dispatch chain collapses every downstream control - the MIME validation was legitimate and still useless, because content checks cannot constrain a filename the attacker chooses. Components that combine public upload endpoints with web-root write paths deserve default-deny treatment from Joomla extension developers, not optional allow-lists that can be silently disabled.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
murrez/CVE-2026-102427

CVE-2026-102427 is an unauthenticated remote code execution flaw in OrdaSoft Joomla Content Construction Kit (OS CCK) — Joomla component com_os_cck.

★ 0

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.