Executive brief
Fabrik is a Joomla extension used to build custom database-driven applications without coding. An unauthenticated attacker can delete all data from any Fabrik list table by sending a simple web request, causing permanent data loss and service disruption for users relying on that data.
Technical details
The vulnerability is an authorization bypass in the list controller's doempty endpoint. The endpoint lacks proper ACL (access control list) checks and allows unauthenticated users to truncate database tables via a plain GET request. An attacker with network access to the Joomla installation can trigger table deletion without authentication or user interaction. The vulnerability affects Fabrik versions before 4.7.2 and has been patched in later releases.
Affected products
- Fabrik Fabrik before 4.7.2
Timeline
- 2026-08-22: disclosed