CVE-2026-48939
KEV PoC moderateUnauthenticated File-Upload RCE in Joomlic iCagenda for Joomla
CISA: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Joomlic's iCagenda event-management extension for Joomla contains an unrestricted file-upload flaw (CWE-434) in its file attachment feature, exploitable over the network without authentication or user interaction (CVSS 4.0 score 10.0). Because the extension accepts arbitrary file types, an attacker can upload a malicious PHP file through the attachment feature and have the web server execute it as PHP code. Successful exploitation gives unauthenticated attackers remote code execution on the affected Joomla site, which typically leads to full site or web-server compromise. Any Joomla installation running the iCagenda extension is affected; the available advisory data specifies no affected or fixed version range, so no version numbers can be stated. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-10 (reportedly exploited as a zero-day, with ransomware use currently unknown), public proof-of-concept code is available, and EPSS assigns roughly a 20% probability of exploitation within 30 days.
What to do: Joomla administrators running iCagenda should update to the latest release published by Joomlic (no specific fixed version is stated in the available data) and, per the KEV required action, apply vendor mitigations in accordance with CISA BOD 26-04, prioritizing internet-exposed instances. Until patched, restrict or disable the file-attachment upload feature (e.g., prevent PHP execution/uploads in the attachments directory) and review web server logs and upload directories for unexpected .php files indicating prior compromise. Given confirmed in-the-wild exploitation reportedly predating disclosure, assume potential compromise and follow CISA's forensics triage requirements where applicable.
| Joomlic iCagenda (Joomla extension) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
- Affected
- iCagenda iCagenda
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Due date
- Ransomware use
- Unknown
- Vendors
- joomlic
- Products
- icagenda
- Ecosystems
- Joomla
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red