Junglewise Threat Intelligence

CVE-2026-57827: RSJoomla RSFiles! unauthenticated arbitrary file upload in frontend controller

CVE-2026-57827 · Severity: info · CVSS 10 · Published 2026-07-11

Executive brief

RSFiles! is a popular file management and download plugin for Joomla websites. A critical security flaw allows anyone on the internet to upload malicious files to the server without needing a username or password. An attacker can use this to take complete control of the website, steal data, or install ransomware.

Technical details

The RSFiles! extension (com_rsfiles) for Joomla contains a critical vulnerability (CWE-434) due to an architectural flaw where security checks and file-writing operations are decoupled. While a 'pre-flight' task performs permission and file-extension validation, the actual file-writing task does not. An unauthenticated attacker can bypass all security gates by sending a direct request to the write task. Because the extension does not enforce file-type restrictions during this direct call and typically stores files in a web-accessible directory with PHP execution enabled, an attacker can upload and execute a .php web shell. This results in full Remote Code Execution (RCE) with the privileges of the web server. The issue is fixed in version 1.17.12.

Affected products

  • RSJoomla! (rsjoomla.com) RSFiles! extension for Joomla 1.0 through 1.17.11

Timeline

  • 2026-07-10: patched: Vendor released version 1.17.12 to address the flaw.
  • 2026-07-11: disclosed: Public disclosure and CVE assignment.

References