Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Fabrik fixes critical unauthenticated RCE

Fabrik for Joomla up to version 4.6.6 contains an unauthenticated remote code execution flaw in its calc element. Tracked as CVE-2026-66915, the issue has a CVSS 4.0 score of 10.0 Critical and is fixed in version 4.6.7.

mySites.guru published research describing the vulnerability as code injection (CWE-94) through Fabrik’s front-end AJAX calculation endpoint. An anonymous visitor could reach the endpoint without authentication or user interaction and cause PHP code to run on the server when the relevant calc element was configured for AJAX recalculation.

The advisory said there was no known exploitation in the wild when it was published, and the issue was not listed in CISA’s Known Exploited Vulnerabilities catalog.

  • Update every Fabrik installation below 4.6.7 as soon as possible.
  • The fixed release supports Joomla 4.2 and later, and Joomla 5.1 through the Joomla 5 series.
  • Fabrik 4.x does not install on Joomla 6, while no patched release was identified for the Fabrik 3.x line used by Joomla 3 sites.
  • Where an update is not immediately possible, unpublish public Fabrik forms and lists as a temporary exposure reduction, then investigate the site for signs of compromise.

Administrators need a valid Fabrik subscription to obtain or install the update through Joomla’s updater or the vendor’s download channel.

Originally reported by mySites.guru.