Junglewise Threat Intelligence

CVE-2026-76600: Fabrik unauthenticated comment deletion

CVE-2026-76600 · Severity: info · Published 2026-08-22

Technologies: Fabrikar.Com Fabrik.

Executive brief

Fabrik is a Joomla extension for building custom database applications and forms. An unauthenticated attacker can delete any comment in the application due to missing access controls on the DeleteComment endpoint, potentially disrupting data integrity and user content.

Technical details

The vulnerability exists in Fabrik versions prior to 4.7.2 where the DeleteComment API endpoint fails to validate user permissions before processing comment deletion requests. An unauthenticated attacker can directly invoke this endpoint with a comment ID to delete any comment in the system without authentication or authorization checks. This is an authorization bypass vulnerability allowing unauthorized data modification. The fix is available in Fabrik 4.7.2 and later versions.

Affected products

  • fabrikar.com Fabrik < 4.7.2

Timeline

  • 2026-08-22: disclosed

References