Executive brief
Fabrik is a Joomla component that allows users to build custom database applications and forms without coding. The order plugin in Fabrik versions before 4.7.2 fails to check user permissions when reordering rows, allowing unauthenticated users to modify the order of data records in lists—potentially disrupting data organization and application workflows.
Technical details
The vulnerability is an authorization bypass in Fabrik's order plugin, where the row reordering function does not perform access control checks. This is a missing authentication/authorization validation issue affecting the plugin's core functionality. An attacker with network access can invoke the order plugin to reorder rows in lists without requiring authentication or proper authorization. While reordering rows may seem low-impact, it can disrupt application logic, data workflows, and integrity if applications depend on row order for processing or display. The issue is fixed in Fabrik version 4.7.2 and later.
Affected products
- Fabrik Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed