CVE-2026-102427 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated Upload RCE
September 30, 2026 · 295 views
OrdaSoft OS CCK for Joomla 1.0.0–8.3.15: unauthenticated front-end task getContent reaches site/uploader.php — GIF/PHP polyglot passes magic-byte check while .php extension from attacker filename is written under web root (CWE-434). CVSS 4.0 10.0 Critical (AT:N). Fixed in 8.3.16+. Python PoC: check, exploit (POCBIT-102427-OK), mass + interactive.
Description
Overview
CVE-2026-102427 — OrdaSoft Joomla Content Construction Kit (OS CCK) (com_os_cck) — unauthenticated remote code execution via unrestricted file upload.
| | | |---|---| | CNA | Joomla! Project (PUBLISHED 2026-09-30) | | Affected | 1.0.0 – 8.3.15 | | Fix | ≥ 8.3.16 | | CWE | CWE-434 (Unrestricted Upload) | | CVSS 4.0 | 10.0 Critical — AT:N |
Front-end task=getContent reaches site/uploader.php with no authentication. Content is validated with a magic-byte image check, but the extension allow-list was commented out in source; the saved filename comes from the attacker. A GIF/PHP polyglot (up.php in the repo) passes the check and executes as PHP.
PoC page: https://pocbit.org/pocs/cve-2026-102427
GitHub: murrez/CVE-2026-102427
CVE.org: CVE-2026-102427
NVD: CVE-2026-102427
Bundled tool (Python 3)
Download cve-2026-102427.py — bundle extractor (writes poc.py, _engine.py, up.php).
pip install requests urllib3 colorama
python cve-2026-102427.py
python poc.py --lab
python poc.py -u https://site.tld --check
python poc.py -u https://site.tld
python poc.py --check fofa_hosts.txt
python poc.py hits.txt
Success marker: POCBIT-102427-OK in HTTP response from uploaded shell path.
Remediation
- Upgrade OS CCK to 8.3.16+ or remove com_os_cck.
- Audit web root and
images/for unexpected .php files. - Inventory other OrdaSoft extensions on the same site (see OrdaSoft ORDER BY SQLi wave).
Legal and ethical use
Authorized security testing and patch validation only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-102425critical
CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-76570critical
CVE-2026-76570 — Joomla JCTables (com_jctables) Unauthenticated SQL Read/Write via JSON API
Joomcode JCTables 1.0.0–1.20.0: unauthenticated front-end JSON tasks (getdatarow, getrow) concatenate table/column names into SQL with broken escaping — arbitrary DB read/write (CWE-89/CWE-862). CVSS 4.0 10.0 Critical (AT:N). Fixed in 1.21.1+. Python PoC proves user row read (POCBIT-76570-OK); check + exploit + mass -j.