Fabrik · Fabrik · CVE-2026-66915
**Name of the Vulnerable Software and Affected Versions**
Fabrik versions prior to 4.6.9
**Description**
An unauthenticated attacker can execute arbitrary code by leveraging the `ajax calc` feature within the calc plugin.
**Recommendations**
Update to version 4.6.9 or later.
As a temporary workaround, restrict access to the `ajax calc` feature of the calc plugin.