Critical 10.0

Joomla JCTables SQLi reads and writes data (CVE-2026-76570) [PoC]

CVE-2026-76570

By Yazoul AI · automated

CVE-2026-76570: JCTables 1.21.1 for Joomla allows unauthenticated SQL injection that reads and writes database records (CVSS 10.0). Update the extension now.

Exploitation confirmed - public proof-of-concept - CVE-2026-76570 is a critical unauthenticated SQL injection in the Joomla extension JCTables 1.21.1 that lets any remote attacker read and write the site’s database without logging in. No official patch has been published; remove or disable the extension until a fixed release lands.

Overview

JCTables is a Joomla extension from joomcode.com that provides front-end table and CRUD (create, read, update, delete) functionality. Version 1.21.1 ships a front-end API controller that performs no Joomla token validation and no authentication check on any of its tasks. That means an anonymous visitor can call the controller directly.

The controller takes table names, column names, and values straight from request parameters and concatenates them into SQL statements. There is no parameter binding, so attacker-supplied strings become part of the query. This applies to both read and write operations, which broadens the impact well beyond a simple data leak.

Because every precondition for exploitation is absent - no account, no token, no user interaction, low complexity, network reachable - the CVSS score is 10.0, the maximum possible.

Impact

An unauthenticated attacker can:

  • Dump the full contents of any table the Joomla database user can reach, including #__users password hashes, email addresses, and session data.
  • Modify or delete rows, injecting rogue administrator accounts or altering published content.
  • In many configurations, escalate from SQL injection to remote code execution by writing files or abusing stacked queries.
  • Pivot into other databases hosted on the same server if the Joomla database account has broad privileges.

For any site running JCTables 1.21.1, treat the database as compromised. Public breach reporting is tracked at breach reports.

Remediation

  1. Disable or uninstall JCTables 1.21.1 immediately. If the extension is not essential, uninstall removes the attack surface entirely.
  2. If you must keep the extension, block access to its front-end API controller at the web server or WAF layer and require authentication at the perimeter.
  3. Check with joomcode.com for a fixed release. As of this writing, no patched version has been confirmed.
  4. Review database logs and Joomla audit logs for suspicious queries, new admin accounts, or unexpected content changes.
  5. Rotate the Joomla database user’s password, restrict that account to the Joomla schema only, and reset all administrator credentials.
  6. Monitor security news for a vendor patch announcement.

Security Insight

This is the second pattern we have seen this quarter where a commercial Joomla extension ships a front-end controller with no token check at all - a design shortcut that turns a convenience feature into a full database compromise. JCTables concatenates request parameters into SQL by hand, which suggests the developer never adopted Joomla’s JDatabaseQuery binding API despite it being standard for over a decade. For site operators, the lesson is that third-party extension code carries the same risk profile as core CMS code, but rarely gets the same review. Inventory every extension, and treat any that expose anonymous write endpoints as untrusted until proven otherwise.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
murrez/CVE-2026-76570

CVE-2026-76570 PoC (PoCbit) — Joomla JCTables (com_jctables) <1.21.1: unauth SQL read/write via front-end JSON API getdatarow/getrow (CVSS 4.0 10.0 AT:N). check + exploit + mass. https://www.cve.org/C

★ 0

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.