Junglewise Threat Intelligence

CVE-2026-76598: Fabrik unauthenticated arbitrary directory listing in onAjax_getFolders

CVE-2026-76598 · Severity: info · Published 2026-08-22

Technologies: Fabrikar.Com Fabrik.

Executive brief

Fabrik is a Joomla extension that allows users to build custom web applications without coding. This vulnerability allows unauthenticated attackers to enumerate arbitrary directories on the server through a method in the elements model, potentially exposing sensitive file paths and directory structures that could facilitate further attacks.

Technical details

The vulnerability exists in the onAjax_getFolders method of Fabrik's elements model, which fails to properly validate or restrict directory listing requests. An unauthenticated attacker can invoke this AJAX method over the network without authentication to retrieve directory listings of arbitrary paths on the server. The vulnerability affects Fabrik versions prior to 4.7.2. While the impact is primarily informational (directory enumeration), it can enable reconnaissance for subsequent attacks targeting sensitive files or directories.

Affected products

  • fabrikar.com Fabrik < 4.7.2

Timeline

  • 2026-08-22: disclosed

References