CRITICAL 9.4 NVD

CVE-2026-88856

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updat

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a package field as its single argument, with no allow-list or is_callable() check of any kind. Any function name compatible with a single argument was directly reachable, including system, exec, shell_exec, and passthru.

References

Published: 2026-09-20 · Source: NVD · Feed updated: 2026-09-20
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-20 via NVD.

Risk Timeline

CVE Disclosed2026-09-20 · -1 days ago

Remediation Resources

Analysis & PoC
www.OrdaSoft.com/
vulnfeed aggregates 14834 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.