CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-07-11
HIGHCVE-2026-57827 +1NATOB2vulnerability

Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)

Two more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS 10.0)

Defender actions

  • Update RSFiles! (com_rsfiles) to ≥ 1.17.12 on every Joomla site now (this is unauthenticated RCE reachable by anyone, not a maintenance-window update) then check the component's web-root /downloads directory for stray .php/.phtml files and review admin accounts for tampering.
  • Update Phoca Download (com_phocadownload) to ≥ 6.1.3; if the frontend member-upload feature was enabled (it is off by default), treat as a priority and hunt the user-upload folder for web shells. Disable member-upload where not required to remove the exposure entirely.
  • As defense-in-depth against the whole wave, configure the web server to deny script execution in Joomla extension upload/download directories.

Analysis

Two more third-party Joomla extensions have patched unrestricted-file-upload flaws that end in remote code execution, both disclosed and fixed on 2026-07-10 by the same researcher (Phil Taylor of mySites.guru) whose source-code audits have been driving an ongoing wave of the identical CWE-434 bug class across the Joomla extension ecosystem. In RSFiles! (com_rsfiles) through 1.17.11, the permission gate and file-type allow-list live in a pre-flight method while the method that actually writes the upload to disk performs no permission check and no extension check; because that write method can be called directly with no site-wide CSRF token and no access check, an anonymous visitor bypasses the gate entirely, and RSFiles!'s default downloads folder sits inside the web root with PHP execution enabled (the protective .htaccess is an opt-in setting that is off by default), so a .php upload lands in a directory that executes it, giving unauthenticated RCE (CVE-2026-57827, CVSS 4.0 10.0) (mySites.guru, 2026-07-10). The vendor RSJoomla! shipped 1.17.12 the same day, "update NOW!". In Phoca Download (com_phocadownload) through 6.1.2, the non-default frontend member-upload feature runs under a different internal upload mode than the one the allow-list check was written for, so the configured file-type restriction is never consulted and a registered member can upload and execute a .php file into the public user-upload folder; authenticated RCE that requires an account plus the member-upload feature enabled (CVE-2026-57828, CVSS 4.0 9.0, fixed in 6.1.3) (mySites.guru, 2026-07-10).

Neither flaw has a published proof-of-concept and neither is confirmed exploited yet, but the wave's earlier members have a short track record from disclosure to in-the-wild abuse: JoomShaper SP Page Builder, Joomlack Page Builder CK, Balbooa Forms and iCagenda all carry the same unauthenticated-or-low-auth file-upload primitive (mySites.guru, 2026-07-10). All four were exploited, and CISA added them to its KEV catalog within days: CVE-2026-48908 (SP Page Builder) and CVE-2026-56290 (Page Builder CK) on 2026-07-07, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) on 2026-07-10 (CISA KEV). Joomla is heavily used across Swiss and European municipal and public-sector websites, and extension-level exposure is independent of core-Joomla patch status, so an otherwise up-to-date site can still be exposed through either component.

Cited evidence

any attacker, without having an account on your website, can upload a .php file in your /downloads directory and execute it.

RSJoomla! (vendor advisory, quoted by mySites.guru)

A logged-in user could upload a file type that should have been rejected, such as a .php script, into the public user-upload folder and then run it.

mySites.guru 2026-07-10

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.