PT-2026-95996 · Ordasoft · Ordasoft Joomla Gallery

·

CVE-2026-88856

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OrdaSoft Joomla Gallery versions prior to 6.2.7
Description An authenticated and privileged remote code execution issue exists in the OrdaSoft Joomla Gallery extension. The updateOSGallery() function, accessible via the task=update osgallery parameter, processes a JSON request body and executes the value provided in the method field as a PHP function. The value from the package field is then passed as the single argument to that function. Because the extension lacks an allow-list or is callable() check, any PHP function accepting one argument can be executed, including system, exec, shell exec, and passthru.
Recommendations Update OrdaSoft Joomla Gallery to version 6.2.7 or later. As a temporary workaround, restrict access to the task=update osgallery functionality to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88856

Affected Products

Ordasoft Joomla Gallery