---
schema: 1
kind: vulnerability
title: "CVE-2026-48939 — iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)"
headline: "CISA KEV-lists an actively-exploited unauth RCE in the iCagenda Joomla extension — RCE hits Joomla 6, auth bypass hits all versions"
summary: >
  CISA added CVE-2026-48939 to its Known Exploited Vulnerabilities catalog on 2026-07-10. The flaw in
  iCagenda, a widely deployed Joomla events/calendar extension, lets an unauthenticated visitor upload a
  PHP web shell through the public event-submission form; on Joomla 6 this yields remote code execution,
  and the underlying access-control bypass affects every Joomla version. It was exploited in the wild
  before a patch existed. Any Joomla site running iCagenda ≤ 4.0.7 (or ≤ 3.9.14 on the legacy branch)
  must update now and hunt for pre-patch compromise — relevant to the many Swiss and European municipal
  and public-sector sites built on Joomla.
discovered_at: "2026-07-10T20:34:32Z"
event_date: "2026-07-10"
run_id: 2026-07-10T2009Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, actively-exploited, pre-auth, zero-day, cisa-kev, poc-public, patch-available]
regions: [global, europe]
sectors: [public-sector, technology]
entities: [trend:joomla-extension-file-upload-rce-wave]
techniques: [T1190, T1505.003]
affected_products: ["JoomliC iCagenda"]
cves:
  - id: CVE-2026-48939
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, poc-public, patch-available]
    affected: "3.2.1–3.9.14 and 4.0.0–4.0.7"
    fixed: "3.9.15 (legacy) / 4.0.8 (current)"
sources:
  - url: "https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/"
    publisher: "mySites.guru"
    date: "2026-06-15"
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog"
    publisher: "CISA"
    date: "2026-07-10"
    role: corroborating
closed_sources: []
evidence:
  - quote: "iCagenda did not maintain its own allow-list of permitted extensions on this path, did not block `.php`, and did not check that the file was actually the image type it claimed to be."
    publisher: "mySites.guru"
  - quote: "A flaw being actively used in the wild, with no fixed version to update to, is the definition of a zero day"
    publisher: "mySites.guru"
verification: multi-source
sourcing_note: "Original discovery, reproduction and technical write-up by mySites.guru (the researcher who received the exploited client's access log and reported it to the vendor); CISA KEV listing on 2026-07-10 independently confirms in-the-wild exploitation. Vendor patch shipped 2026-06-15/16; CVE published by the Joomla security team 2026-06-20."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 1
watchlist_hit: false
actions:
  - "Update iCagenda to ≥ 4.0.8 (current branch) or ≥ 3.9.15 (legacy branch) on every Joomla site now; unpublishing the component does not protect it — the submit endpoint and any uploaded files stay reachable."
  - "On Joomla 6 sites assume pre-patch compromise: hunt for any file that should not exist under images/icagenda/frontend/attachments/ (a .php file there is a web shell until proven otherwise), and if found, treat the whole site as compromised and rotate Joomla secrets."
  - "On Joomla 2.5–5 sites, check the event-submission queue for anonymously-created unapproved events as a sign the access bypass was used."
migrated_from: null
---

iCagenda's frontend "Submit an Event" form processed uploaded attachments by keeping the visitor-supplied file extension and writing the file straight to `images/icagenda/frontend/attachments/` under the web root, with no extension allow-list and no content-type check ([mySites.guru, 2026-06-15](https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/)). Crucially, the "who may submit an event" access check was applied only in the *view* that decides whether to draw the form, never in the *controller* that processed the submission — so an attacker harvested a form token from any public iCagenda page and POSTed directly to the processing endpoint, bypassing the "Registered users only" setting entirely with no account. On Joomla 6 the uploaded `.php` file is web-served and executes, giving unauthenticated remote code execution; on Joomla 2.5 through 5, core upload filtering blocks the shell, but the same authorization bypass still lets an anonymous visitor create unapproved events ([mySites.guru, 2026-06-15](https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/)). CISA's dated alert confirms this as one of exactly two KEV additions on 2026-07-10 ([CISA, 2026-07-10](https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog)).

This is the fourth Joomla third-party extension in roughly a month to ship the same unauthenticated-upload-to-RCE shape surfaced by the same researcher, after the SP Page Builder, Page Builder CK and Balbooa Forms cluster — a recurring third-party-extension exposure for the Joomla estates common across Swiss and European municipal and public-sector web infrastructure.

**Defender takeaway:** the reachable primary detection is in web/application access logs — an anonymous-session POST to the com_icagenda submission endpoint followed almost immediately by a GET fetching a `.php` path under the attachments directory is the exploitation sequence; file-integrity monitoring on upload directories that flags any newly-created executable-extension file is the durable, tool-independent signal. **Triage:** on a patched instance (4.0.8/3.9.15) the upload runs through Joomla's `MediaHelper` allow-list, so legitimate event submissions can only ever attach non-executable types (images, PDFs, documents) — any `.php` (or double-extension such as `.php.jpg`) file under `images/icagenda/frontend/attachments/` is not something a legitimate submission can produce and is the clean discriminator once that directory's baseline is known. Because exploitation predates the fix, patching stops the next attempt but does not remediate a shell dropped earlier — Joomla 6 sites must be checked regardless of current version.
