Junglewise Threat Intelligence

CVE-2026-76606: Fabrik path traversal via image element

CVE-2026-76606 · Severity: info · Published 2026-08-22

Technologies: Fabrikar Fabrik.

Executive brief

Fabrik is a Joomla extension that enables users to build custom database-driven applications without coding. A path traversal vulnerability in the image element handling allows an attacker to access files outside the intended directory, potentially exposing sensitive configuration files and application data.

Technical details

The vulnerability is a path traversal (directory traversal) flaw in Fabrik's image element processing, affecting versions before 4.7.2. An attacker can manipulate image element parameters to traverse the file system using relative path sequences (e.g., `../`), potentially reading arbitrary files accessible to the web server process. The attack vector and prerequisites (authentication requirement, network accessibility) are not fully detailed in the available advisory text. Versions 4.7.2 and later contain fixes for this issue.

Affected products

  • Fabrikar Fabrik before 4.7.2

References