CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave

cve · CVE-2026-57827

Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
Two more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector · regions: europe, switzerland
Sources cited
4
3 hosts

Action items (3)

Do-now tasks recorded on the entries about CVE-2026-57827, newest first. Check the date before acting on an older one.

  • Update RSFiles! (com_rsfiles) to ≥ 1.17.12 on every Joomla site now (this is unauthenticated RCE reachable by anyone, not a maintenance-window update) then check the component's web-root /downloads directory for stray .php/.phtml files and review admin accounts for tampering.
    2026-07-11CVE-2026-57827 +1
  • Update Phoca Download (com_phocadownload) to ≥ 6.1.3; if the frontend member-upload feature was enabled (it is off by default), treat as a priority and hunt the user-upload folder for web shells. Disable member-upload where not required to remove the exposure entirely.
    2026-07-11CVE-2026-57827 +1
  • As defense-in-depth against the whole wave, configure the web server to deny script execution in Joomla extension upload/download directories.
    2026-07-11CVE-2026-57827 +1

Defender insights

What each entry about CVE-2026-57827 tells a defender to do, newest first.

2026-07-11HIGHTwo more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS 10.0)

Detection

Story timeline

  1. 2026-07-11Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)
    trending-vulnerabilitiesTwo more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS 10.0)
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • PersistenceServer Software Component: Web Shell

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828 · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828 · ATT&CK page ↗

Entries about Joomla RSFiles! (com_rsfiles) unauthenticated file-upload RCE (CVSS 4.0 10.0); part of the mySites.guru Joomla-extension CWE-434 wave (1)

2026-07-11 · view entry permalink →

Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)

Two more third-party Joomla extensions have patched unrestricted-file-upload flaws that end in remote code execution, both disclosed and fixed on 2026-07-10 by the same researcher (Phil Taylor of mySites.guru) whose source-code audits have been driving an ongoing wave of the identical CWE-434 bug class across the Joomla extension ecosystem. In RSFiles! (com_rsfiles) through 1.17.11, the permission gate and file-type allow-list live in a pre-flight method while the method that actually writes the upload to disk performs no permission check and no extension check; because that write method can be called directly with no site-wide CSRF token and no access check, an anonymous visitor bypasses the gate entirely, and RSFiles!'s default downloads folder sits inside the web root with PHP execution enabled (the protective .htaccess is an opt-in setting that is off by default), so a .php upload lands in a directory that executes it, giving unauthenticated RCE (CVE-2026-57827, CVSS 4.0 10.0) (mySites.guru, 2026-07-10). The vendor RSJoomla! shipped 1.17.12 the same day, "update NOW!". In Phoca Download (com_phocadownload) through 6.1.2, the non-default frontend member-upload feature runs under a different internal upload mode than the one the allow-list check was written for, so the configured file-type restriction is never consulted and a registered member can upload and execute a .php file into the public user-upload folder; authenticated RCE that requires an account plus the member-upload feature enabled (CVE-2026-57828, CVSS 4.0 9.0, fixed in 6.1.3) (mySites.guru, 2026-07-10).

Neither flaw has a published proof-of-concept and neither is confirmed exploited yet, but the wave's earlier members have a short track record from disclosure to in-the-wild abuse: JoomShaper SP Page Builder, Joomlack Page Builder CK, Balbooa Forms and iCagenda all carry the same unauthenticated-or-low-auth file-upload primitive (mySites.guru, 2026-07-10). All four were exploited, and CISA added them to its KEV catalog within days: CVE-2026-48908 (SP Page Builder) and CVE-2026-56290 (Page Builder CK) on 2026-07-07, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) on 2026-07-10 (CISA KEV). Joomla is heavily used across Swiss and European municipal and public-sector websites, and extension-level exposure is independent of core-Joomla patch status, so an otherwise up-to-date site can still be exposed through either component.

any attacker, without having an account on your website, can upload a .php file in your /downloads directory and execute it.

RSJoomla! (vendor advisory, quoted by mySites.guru)

A logged-in user could upload a file type that should have been rejected, such as a .php script, into the public user-upload folder and then run it.

mySites.guru 2026-07-10
vulnerability11 Jul 13:00Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • mysites.guru2 (50%)
  • cisa.gov1 (25%)
  • rsjoomla.com1 (25%)