POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
← Blog

Joomla JCTables SQLi (CVE-2026-76570): Anonymous JSON getdatarow and CVSS 10.0

Admin · October 5, 2026 · 5 views

When your “JSON CRUD widget” is the database

Joomcode JCTables (com_jctables) exposes a front-end JSON API for table-style data on Joomla sites. CVE-2026-76570 (Joomla! Project CNA, CVSS 4.0 10.0 Critical, CWE-89 / CWE-862, AT:N) lets anonymous callers reach tasks such as getdatarow and getrow without token or ACL—and builds SQL from attacker-influenced table and column names with broken escaping in ladb_escape().

That is not a blind boolean in a search box; it is direct row reads from tables like {prefix}users, including password hashes, with a single GET-shaped API call.

Lab tooling and read proof (POCBIT-76570-OK): CVE-2026-76570 on pocbit.org. Repository: murrez/CVE-2026-76570.

| | | |---|---| | Affected | 1.0.0 – 1.20.0 | | Fixed | ≥ 1.21.1 (2026-08-05) |

Why this CVE is a priority outlier

Many Joomla issues need a specific module placement or editor workflow. 76570 is network-exposed JSON on option=com_jctables&format=json—closer to “leaky micro-API” than classic form SQLi. Write primitives in advisory text compound impact; even read-only proof is enough to drive credential recovery and follow-on compromise.

Do not confuse with CVE-2026-102427 (OrdaSoft upload RCE) or order-by SQLi on a different OrdaSoft surface—JCTables is Joomcode, different package, different tasks.

Defender checklist

| # | Action | Detail | |---|--------|--------| | 1 | Extension inventory for com_jctables | Administrator → System → Extensions | | 2 | Upgrade to ≥ 1.21.1 or uninstall | Vendor release 2026-08-05 | | 3 | Log review | Anonymous getdatarow, getrow, format=json bursts | | 4 | DB monitoring | Unexpected SELECT patterns from web user | | 5 | Post-patch | Force password resets if exploit window overlapped your logs |

Cross-read: Joomla security checklist (2026), SQL injection types and prevention, authentication bypass — what to check (hash theft → admin login).

API surface to recognize

Typical read proof (authorized testing):

GET index.php?option=com_jctables&format=json&task=getdatarow&tn={prefix}users&idx=id&rid=1

Boolean-style probes may use getrow with quote-breakout fragments in idx. Block or alert on these task names from untrusted IPs during patch rollout.

Patch validation in a lab

  1. Joomla VM with JCTables ≤ 1.20.0.
  2. Run bundle check, then read proof with known table prefix (jos_, etc.).
  3. Upgrade to 1.21.1+; confirm tasks reject injection or require auth.

See CVE PoC testing step-by-step and safe PoC lab setup.

FAQ

We only use JCTables in the admin backend—safe?

If front-end format=json routes remain registered for anonymous users, exposure depends on routing—not where editors click. Verify version and upgrade.

Is WAF enough?

Temporary rules on com_jctables JSON tasks help; vendor fix removes the unsafe string concatenation.

Bottom line

CVE-2026-76570 punishes teams that treat third-party JSON APIs as “just UI glue.” Inventory com_jctables, patch to 1.21.1+, and assume any anonymous SQL read of users triggers a credential incident until proven otherwise.