OrdaSoft OS CCK Upload RCE (CVE-2026-102427): GIF Polyglot, PHP on Disk, CVSS 10.0
Admin · October 3, 2026 · 5 views
CVSS 10.0 on a CCK upload path
OrdaSoft OS Content Construction Kit (com_os_cck) is a long-lived Joomla extension for custom content types and front-end uploads. CVE-2026-102427 (Joomla! Project CNA, CVSS 4.0 10.0 Critical, CWE-434, AT:N) is unauthenticated remote code execution: a public task=getContent flow reaches site/uploader.php without login, accepts a GIF magic-byte polyglot, and writes the attacker’s .php filename to a web-served path because extension allow-list logic was effectively disabled in vulnerable builds.
Public PoC: CVE-2026-102427 on pocbit.org. Repository: murrez/CVE-2026-102427.
| | | |---|---| | Affected | 1.0.0 – 8.3.15 | | Fixed | ≥ 8.3.16 | | Verify marker | POCBIT-102427-OK (PoC tooling) |
Why magic-byte checks failed here
Upload filters often inspect file content (GIF header) but store using client-supplied names. When getimagesize()-style validation passes on a polyglot and extension enforcement is missing or commented out, the server persists shell.php (or similar) under components/com_os_cck/ upload trees—classic unrestricted upload of dangerous types with no authentication.
This is simpler than SQLi chains: one POST, one file, immediate code execution on typical Apache/nginx+PHP configs.
Defender checklist
| # | Action | Detail |
|---|--------|--------|
| 1 | Inventory com_os_cck version | Manifest under administrator/components/com_os_cck |
| 2 | Upgrade to ≥ 8.3.16 immediately | Joomla extension manager or vendor package |
| 3 | Hunt unexpected .php under CCK upload dirs | Post-incident hygiene |
| 4 | WAF (temporary) | Rate-limit option=com_os_cck + task=getContent POST multipart |
| 5 | Correlate with CVE Detector Joomla signals | Map CVE to installed version before scanners arrive |
Cross-read: Joomla security checklist (2026), file upload vulnerabilities, Joomla extensions security basics.
Discovery hints (your assets only)
body="com_os_cck" || body="/components/com_os_cck/"
index.php?option=com_os_cck
Version exposure may include component manifests when reachable—use for your asset inventory only.
Patch validation in a lab
- Joomla 4/5 VM with OS CCK ≤ 8.3.15 and upload feature enabled.
- Run PoC check, then controlled exploit with
--labor isolated host. - Upgrade to 8.3.16+; confirm upload rejected or extension enforced.
See safe PoC lab setup and step-by-step CVE PoC testing.
FAQ
We do not expose CCK forms publicly—safe?
If the vulnerable task is reachable without auth on the front end, network reachability matters more than “hidden menu.” Upgrade regardless.
Can WAF replace the vendor fix?
Virtual patch on upload parameters helps during maintenance; 8.3.16+ restores proper extension handling.
Bottom line
CVE-2026-102427 is a reminder that CCK and form builders are RCE surfaces when upload handlers trust magic bytes but not filenames. Name the installed version, patch OrdaSoft on every Joomla property, and audit upload directories—AT:N means opportunistic mass exploit is in scope for unpatched hosts.