Security
iCagenda flaw enabled unauthenticated RCE on Joomla 6
mySites.guru has reported a critical iCagenda vulnerability that allowed unauthenticated attackers to upload executable files and achieve remote code execution on Joomla 6 sites. The issue was being exploited before JoomliC released a fix.
The affected extension is iCagenda, developed by JoomliC. The primary issue is an improper access-control flaw (CWE-284) in the frontend event submission process. It is tracked as CVE-2026-48939 and carries a CVSS 4.0 score of 10.0 (Critical).
According to research published by mySites.guru, the upload-to-code-execution chain required no login and worked on Joomla 6, where core upload protections did not block the dangerous file. Earlier Joomla versions were still affected by an access-control bypass that could allow anonymous users to submit unapproved events.
- 4.x releases through
4.0.7: update to4.0.8, released 15 June 2026. - 3.2.1 through
3.9.14: update to3.9.15, released 16 June 2026.
Administrators should update immediately and inspect the iCagenda attachment directory for unexpected files, particularly on Joomla 6. Treat suspicious files as evidence of compromise and investigate the wider site. Unpublishing the component does not provide protection. Automated attacks were reported in the wild from 15 June 2026.
Originally reported by mySites.guru.