Junglewise Threat Intelligence

CVE-2026-76599: Fabrik unauthenticated database table and prefix disclosure via ajax_tables

CVE-2026-76599 · Severity: info · Published 2026-08-22

Technologies: Fabrik. Vendors: Fabrik.

Executive brief

Fabrik is a Joomla component for building custom database-driven web applications without programming knowledge. A vulnerability in the ajax_tables method allows unauthenticated attackers to enumerate database table names, column structures, and table prefixes—sensitive information that can inform further attacks against the application's data layer.

Technical details

The ajax_tables method in Fabrik's elements model lacks proper authentication checks, allowing unauthenticated requests to retrieve lists of arbitrary database tables and their columns. The vulnerability enables information disclosure of database structure and naming conventions (table prefixes), which typically requires administrative access. No authentication is required to exploit this, and the attack is remotely accessible via HTTP. An attacker can map the application's database schema and table naming patterns to facilitate subsequent attacks such as SQL injection or targeted data extraction. This vulnerability affects Fabrik versions prior to 4.7.2.

Affected products

  • Fabrik Fabrik < 4.7.2

Timeline

  • 2026-08-22: disclosed

References

Related threats