Joomla JCTables SQLi reads and writes data (CVE-2026-76570) [PoC]
CVE-2026-76570
CVE-2026-76570: JCTables 1.21.1 for Joomla allows unauthenticated SQL injection that reads and writes database records (CVSS 10.0). Update the extension now.
Exploitation confirmed - public proof-of-concept - CVE-2026-76570 is a critical unauthenticated SQL injection in the Joomla extension JCTables 1.21.1 that lets any remote attacker read and write the site’s database without logging in. No official patch has been published; remove or disable the extension until a fixed release lands.
Overview
JCTables is a Joomla extension from joomcode.com that provides front-end table and CRUD (create, read, update, delete) functionality. Version 1.21.1 ships a front-end API controller that performs no Joomla token validation and no authentication check on any of its tasks. That means an anonymous visitor can call the controller directly.
The controller takes table names, column names, and values straight from request parameters and concatenates them into SQL statements. There is no parameter binding, so attacker-supplied strings become part of the query. This applies to both read and write operations, which broadens the impact well beyond a simple data leak.
Because every precondition for exploitation is absent - no account, no token, no user interaction, low complexity, network reachable - the CVSS score is 10.0, the maximum possible.
Impact
An unauthenticated attacker can:
- Dump the full contents of any table the Joomla database user can reach, including
#__userspassword hashes, email addresses, and session data. - Modify or delete rows, injecting rogue administrator accounts or altering published content.
- In many configurations, escalate from SQL injection to remote code execution by writing files or abusing stacked queries.
- Pivot into other databases hosted on the same server if the Joomla database account has broad privileges.
For any site running JCTables 1.21.1, treat the database as compromised. Public breach reporting is tracked at breach reports.
Remediation
- Disable or uninstall JCTables 1.21.1 immediately. If the extension is not essential, uninstall removes the attack surface entirely.
- If you must keep the extension, block access to its front-end API controller at the web server or WAF layer and require authentication at the perimeter.
- Check with joomcode.com for a fixed release. As of this writing, no patched version has been confirmed.
- Review database logs and Joomla audit logs for suspicious queries, new admin accounts, or unexpected content changes.
- Rotate the Joomla database user’s password, restrict that account to the Joomla schema only, and reset all administrator credentials.
- Monitor security news for a vendor patch announcement.
Security Insight
This is the second pattern we have seen this quarter where a commercial Joomla extension ships a front-end controller with no token check at all - a design shortcut that turns a convenience feature into a full database compromise. JCTables concatenates request parameters into SQL by hand, which suggests the developer never adopted Joomla’s JDatabaseQuery binding API despite it being standard for over a decade. For site operators, the lesson is that third-party extension code carries the same risk profile as core CMS code, but rarely gets the same review. Inventory every extension, and treat any that expose anonymous write endpoints as untrusted until proven otherwise.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| murrez/CVE-2026-76570 CVE-2026-76570 PoC (PoCbit) — Joomla JCTables (com_jctables) <1.21.1: unauth SQL read/write via front-end JSON API getdatarow/getrow (CVSS 4.0 10.0 AT:N). check + exploit + mass. https://www.cve.org/C | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listin...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate ...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes eac...
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to i...