CVE-2026-73327
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extractin
CVSS
7.6
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 12 ago 2026 · Última mod.: 12 ago 2026 · CWE-22
Sin historial EPSS suficiente todavía.
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.
- github.comhttps://github.com/joomla/joomla-cms
- github.comhttps://github.com/joomla/joomla-cms/commit/9678a171d37e1e10ca75c9124bdafe20fe14fa5b
- github.comhttps://github.com/joomla/joomla-cms/pull/48057
- www.vulncheck.comhttps://www.vulncheck.com/advisories/joomla-zip-slip-path-traversal-via-com-joomlaupdate-extract-php