CVE-2026-84048 Details
Description
Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.
An unauthenticated arbitrary file upload vulnerability has been identified in the JoomGallery extension for Joomla, affecting versions prior to 4.4.1. The vulnerability arises from the TUS endpoint, which allows arbitrary file uploads without proper validation of file names or extensions. While the TUS endpoint can be exploited to upload files, executing code from the uploaded files requires non-standard server configurations.
Users are advised to update to JoomGallery version 4.4.1 or later. For those still using Joomla 4, it is recommended to update to Joomla 5 or 6, as JoomGallery will no longer support Joomla 4 versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.joomgalleryfriends.net/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| JoomGallery friends JoomGallery | < 4.4.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 19, 2026 | CVE Modified | [email protected] |
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion