POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-102427 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated Upload RCE

September 30, 2026 · 295 views

OrdaSoft OS CCK for Joomla 1.0.0–8.3.15: unauthenticated front-end task getContent reaches site/uploader.php — GIF/PHP polyglot passes magic-byte check while .php extension from attacker filename is written under web root (CWE-434). CVSS 4.0 10.0 Critical (AT:N). Fixed in 8.3.16+. Python PoC: check, exploit (POCBIT-102427-OK), mass + interactive.

#joomla#ordasoft#com_os_cck#cck#rce#file-upload#unauthenticated#cwe-434#critical

CVE:

CVE-2026-102427

Date:

2026-09-30

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-102427 — OrdaSoft Joomla Content Construction Kit (OS CCK) (com_os_cck) — unauthenticated remote code execution via unrestricted file upload.

| | | |---|---| | CNA | Joomla! Project (PUBLISHED 2026-09-30) | | Affected | 1.0.0 – 8.3.15 | | Fix | ≥ 8.3.16 | | CWE | CWE-434 (Unrestricted Upload) | | CVSS 4.0 | 10.0 Critical — AT:N |

Front-end task=getContent reaches site/uploader.php with no authentication. Content is validated with a magic-byte image check, but the extension allow-list was commented out in source; the saved filename comes from the attacker. A GIF/PHP polyglot (up.php in the repo) passes the check and executes as PHP.

PoC page: https://pocbit.org/pocs/cve-2026-102427

GitHub: murrez/CVE-2026-102427

CVE.org: CVE-2026-102427

NVD: CVE-2026-102427

Bundled tool (Python 3)

Download cve-2026-102427.py — bundle extractor (writes poc.py, _engine.py, up.php).

pip install requests urllib3 colorama

python cve-2026-102427.py
python poc.py --lab
python poc.py -u https://site.tld --check
python poc.py -u https://site.tld
python poc.py --check fofa_hosts.txt
python poc.py hits.txt

Success marker: POCBIT-102427-OK in HTTP response from uploaded shell path.

Remediation

  1. Upgrade OS CCK to 8.3.16+ or remove com_os_cck.
  2. Audit web root and images/ for unexpected .php files.
  3. Inventory other OrdaSoft extensions on the same site (see OrdaSoft ORDER BY SQLi wave).

Legal and ethical use

Authorized security testing and patch validation only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →