Executive brief
Fabrik is a Joomla extension that allows users to build custom applications with forms and lists without coding knowledge. The form.inlineedit controller lacks access control checks, allowing unauthorized users to view database records they should not have access to.
Technical details
The vulnerability is an authorization bypass in the form.inlineedit controller of Fabrik versions prior to 4.7.2. The vulnerable component fails to perform access control checks before returning row data, allowing an attacker to retrieve database records via unauthenticated requests. No authentication or special preconditions are required; the attacker only needs network access to the Fabrik installation. This enables unauthorized information disclosure of sensitive data stored in database rows. The issue is fixed in Fabrik 4.7.2 and later.
Affected products
- Fabrik Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed