Executive brief
Fabrik is a Joomla application builder that allows users to create custom forms and data applications. A vulnerability in the PHP form element allows unauthenticated attackers to execute arbitrary PHP code, potentially compromising the entire web application and underlying server. This could lead to data theft, website defacement, malware installation, or complete server takeover.
Technical details
The PHP form element in Fabrik versions below 4.7.2 fails to properly sanitize or restrict user-supplied input, allowing arbitrary PHP code execution. The vulnerability is accessible without authentication, meaning any unauthenticated attacker with network access to the Fabrik installation can craft malicious requests containing PHP code. By submitting specially crafted form data through the PHP element, an attacker can execute arbitrary server-side PHP commands with the privileges of the web server process. The vulnerability affects Fabrik versions prior to 4.7.2; patched versions should be applied immediately.
Affected products
- Fabrikar Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed