Junglewise Threat Intelligence

CVE-2026-88856: OrdaSoft Joomla Gallery authenticated remote code execution

CVE-2026-88856 · Severity: info · Published 2026-09-20

Technologies: OrdaSoft Joomla Gallery. Vendors: OrdaSoft.

Executive brief

OrdaSoft Joomla Gallery is a content management extension that allows website administrators to manage image galleries on Joomla-based websites. An authenticated administrator can execute arbitrary system commands on the web server by sending a specially crafted request to the update function, potentially allowing full compromise of the website and underlying server.

Technical details

The updateOSGallery() method in OrdaSoft Joomla Gallery accepts a JSON request body containing method and package fields without validating or restricting which PHP functions can be called. An attacker with administrative privileges can invoke arbitrary single-argument PHP functions (such as system, exec, shell_exec, or passthru) by specifying them in the method field and passing shell commands via the package field. No fix information is provided in the advisory.

Affected products

  • OrdaSoft Joomla Gallery before 6.2.7

Timeline

  • 2026-09-20: disclosed

References

Related threats