Junglewise Threat Intelligence

CVE-2026-88857: OrdaSoft Joomla Gallery arbitrary file upload and code execution

CVE-2026-88857 · Severity: info · Published 2026-09-20

Technologies: OrdaSoft Joomla Gallery. Vendors: OrdaSoft.

Executive brief

OrdaSoft Joomla Gallery is a media management extension for Joomla websites. The extension's watermark feature fails to validate uploaded file types, allowing authenticated administrators to upload and execute PHP code by masquerading files with fake image headers. An attacker with admin privileges can gain complete control over the Joomla website and its server.

Technical details

The saveWatermark() function in OrdaSoft Joomla Gallery accepts file uploads without extension validation, content-type checking, or filename sanitization, storing them in a web-accessible directory. An authenticated user with core.manage privileges can upload a PHP file with a spoofed image Content-Type header, then directly execute it via HTTP request. This is a post-authentication arbitrary file upload leading to remote code execution.

Affected products

  • OrdaSoft Joomla Gallery < 6.2.7

Timeline

  • 2026-09-20: disclosed

References

Related threats