Junglewise Threat Intelligence

CVE-2026-48946: Joomla K2 Extension Unrestricted File Upload in Article Attachments

CVE-2026-48946 · Severity: info · CVSS 8.8 · Published 2026-06-25

Technologies: JoomlaWorks K2. Vendors: JoomlaWorks.

Executive brief

A vulnerability in the K2 content management extension for Joomla allows users with 'Author' permissions to upload malicious files. By uploading a PHP script as an article attachment, an attacker can gain full control over the web server. This could lead to the theft of sensitive data, website defacement, or a complete service outage.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the K2 frontend article-attachment upload path. The application fails to validate or sanitize file extensions, allowing files with a `.php` extension to be uploaded to the `/media/k2/attachments/` directory. Because standard Apache mod_php configurations execute files ending in `.php`, an authenticated user with 'Author' privileges can upload a web shell and execute arbitrary PHP code in the context of the web server user. The vulnerability affects K2 versions 1.0 through 2.26.

Affected products

  • getk2.com K2 extension for Joomla 1.0-2.26

Timeline

  • 2026-06-25: disclosed: CVE published by Joomla! Project

References

Related threats