Junglewise Threat Intelligence

CVE-2026-97163: lomart.fr UP plugin unauthenticated remote code installation

CVE-2026-97163 · Severity: info · Published 2026-09-26

Executive brief

The UP plugin extension for Joomla allows unauthenticated attackers to install arbitrary code remotely on affected systems. This vulnerability could enable an attacker to take complete control of a website, access sensitive data, or use the compromised server for malicious purposes without requiring valid credentials.

Technical details

The UP plugin extension for Joomla contains an unauthenticated remote code installation vulnerability affecting versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29. The vulnerability allows unauthenticated network-based attackers to install arbitrary code without any prior authentication or user interaction, leading to complete system compromise.

Affected products

  • lomart.fr UP plugin 5.0.0-5.2.0, 6.0.0-6.0.29

Timeline

  • 2026-09-26: disclosed

References

Related threats