PT-2026-61679 · Joomla · Jmedia

CVE-2026-60032

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions JMedia versions prior to 1.6.0
Description The Joomla extension JMedia allows authenticated users to perform arbitrary file uploads, which can lead to Remote Code Execution (RCE). This occurs because the system permits the upload and writing of executable files, including those with polyglot filenames, and the chmod function fails to strip execute bits from the uploaded files.
Recommendations Update JMedia to version 1.6.0 or later.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60032

Affected Products

Jmedia