Junglewise Threat Intelligence

CVE-2026-94132: AcyMailing remote code execution in mailbox action

CVE-2026-94132 · Severity: info · Published 2026-09-26

Executive brief

AcyMailing is an email marketing platform for Joomla and WordPress that manages email campaigns and subscriber communications. The Enterprise extension before version 11.1.0 contains a vulnerability that allows attackers to upload and execute malicious PHP files by emailing a monitored mailbox, potentially leading to complete website compromise and unauthorized data access.

Technical details

The vulnerability exists in the mailbox action feature where MIME parts of incoming emails are saved to the web-accessible directory media/com_acym/upload/ without file extension validation. An attacker with access to a monitored mailbox can craft emails containing PHP files that will be extracted and written to the web root, enabling remote code execution. No authentication is required beyond ability to send email to the configured mailbox.

Affected products

  • acymailing.com AcyMailing Enterprise < 11.1.0

Timeline

  • 2026-09-26: disclosed

References