Junglewise Threat Intelligence

CVE-2026-97161: Joomla UP plugin path traversal and file access

CVE-2026-97161 · Severity: info · Published 2026-09-26

Executive brief

The Joomla UP plugin from lomart.fr contains multiple path traversal and file access vulnerabilities that could allow attackers to read or access files outside of their intended directory on a web server. An attacker could potentially retrieve sensitive configuration files, database credentials, or other protected information without authentication. This affects versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29.

Technical details

Multiple path traversal vectors exist in the UP Joomla extension, allowing unauthenticated file access through directory traversal attacks. The vulnerabilities likely stem from insufficient input validation on file path parameters. Attackers can exploit these to read arbitrary files on the server filesystem.

Affected products

  • lomart.fr UP 5.0.0-5.2.0, 6.0.0-6.0.29

Timeline

  • 2026-09-26: disclosed

References

Related threats