Executive brief
Fabrik is a Joomla extension for building custom data collection and management applications. A missing access control check in the download element allows unauthorized users to bypass permission restrictions and access files they should not be able to download, potentially exposing sensitive data.
Technical details
The vulnerability is an authorization bypass (missing ACL check) in the download element component of Fabrik. The download functionality fails to properly validate user permissions before allowing file downloads, enabling an attacker to access restricted files without proper authorization. The attack vector is network-based and does not require special preconditions beyond network access to the affected Joomla installation. An attacker can exploit this to retrieve sensitive files or data intended to be access-controlled. The vulnerability is fixed in Fabrik version 4.7.2 and later.
Affected products
- Fabrik Fabrik < 4.7.2
Timeline
- 2026-08-22: disclosed