Joomla JCTables SQLi (CVE-2026-76570): Anonymous JSON getdatarow and CVSS 10.0
Admin · October 5, 2026 · 5 views
When your “JSON CRUD widget” is the database
Joomcode JCTables (com_jctables) exposes a front-end JSON API for table-style data on Joomla sites. CVE-2026-76570 (Joomla! Project CNA, CVSS 4.0 10.0 Critical, CWE-89 / CWE-862, AT:N) lets anonymous callers reach tasks such as getdatarow and getrow without token or ACL—and builds SQL from attacker-influenced table and column names with broken escaping in ladb_escape().
That is not a blind boolean in a search box; it is direct row reads from tables like {prefix}users, including password hashes, with a single GET-shaped API call.
Lab tooling and read proof (POCBIT-76570-OK): CVE-2026-76570 on pocbit.org. Repository: murrez/CVE-2026-76570.
| | | |---|---| | Affected | 1.0.0 – 1.20.0 | | Fixed | ≥ 1.21.1 (2026-08-05) |
Why this CVE is a priority outlier
Many Joomla issues need a specific module placement or editor workflow. 76570 is network-exposed JSON on option=com_jctables&format=json—closer to “leaky micro-API” than classic form SQLi. Write primitives in advisory text compound impact; even read-only proof is enough to drive credential recovery and follow-on compromise.
Do not confuse with CVE-2026-102427 (OrdaSoft upload RCE) or order-by SQLi on a different OrdaSoft surface—JCTables is Joomcode, different package, different tasks.
Defender checklist
| # | Action | Detail |
|---|--------|--------|
| 1 | Extension inventory for com_jctables | Administrator → System → Extensions |
| 2 | Upgrade to ≥ 1.21.1 or uninstall | Vendor release 2026-08-05 |
| 3 | Log review | Anonymous getdatarow, getrow, format=json bursts |
| 4 | DB monitoring | Unexpected SELECT patterns from web user |
| 5 | Post-patch | Force password resets if exploit window overlapped your logs |
Cross-read: Joomla security checklist (2026), SQL injection types and prevention, authentication bypass — what to check (hash theft → admin login).
API surface to recognize
Typical read proof (authorized testing):
GET index.php?option=com_jctables&format=json&task=getdatarow&tn={prefix}users&idx=id&rid=1
Boolean-style probes may use getrow with quote-breakout fragments in idx. Block or alert on these task names from untrusted IPs during patch rollout.
Patch validation in a lab
- Joomla VM with JCTables ≤ 1.20.0.
- Run bundle check, then read proof with known table prefix (
jos_, etc.). - Upgrade to 1.21.1+; confirm tasks reject injection or require auth.
See CVE PoC testing step-by-step and safe PoC lab setup.
FAQ
We only use JCTables in the admin backend—safe?
If front-end format=json routes remain registered for anonymous users, exposure depends on routing—not where editors click. Verify version and upgrade.
Is WAF enough?
Temporary rules on com_jctables JSON tasks help; vendor fix removes the unsafe string concatenation.
Bottom line
CVE-2026-76570 punishes teams that treat third-party JSON APIs as “just UI glue.” Inventory com_jctables, patch to 1.21.1+, and assume any anonymous SQL read of users triggers a credential incident until proven otherwise.