CVE-2026-48939
published 2026-06-20CVE-2026-48939: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-13
Exploited in the wild
EPSS
82.50%
99.6th percentile
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| icagenda.com | icagenda_extension_for_joomla | — | — |
| joomlic | icagenda | >= 3.2.1 < 3.9.15 | 3.9.15 |
| joomlic | icagenda | >= 4.0.0 < 4.0.8 | 4.0.8 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability allows unrestricted file upload via the iCagenda extension's file attachment feature, enabling PHP code upload and execution. Monitor for PHP file uploads in Joomla iCagenda attachment directories. ↗
- →Flag any uploaded files with PHP extensions (e.g., .php, .php5, .phtml, .phar) in Joomla iCagenda component upload/attachment paths as potential webshell drops. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
ghsa_unreviewed·2026-06-20
CVE-2026-48939 [CRITICAL] CWE-284 A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
VulDB
iCagenda Extension up to 3.9.14/4.0.7 on Joomla access control (EUVD-2026-38109)
vuldb·2026-06-20·CVSS 10.0
CVE-2026-48939 [CRITICAL] iCagenda Extension up to 3.9.14/4.0.7 on Joomla access control (EUVD-2026-38109)
A vulnerability identified as critical has been detected in iCagenda Extension up to 3.9.14/4.0.7 on Joomla. This impacts an unknown function. This manipulation causes improper access controls.
This vulnerability is registered as CVE-2026-48939. Remote exploitation of the attack is possible. No exploit is available.
VulnCheck
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-48939 [CRITICAL] CWE-434 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Affected: iCagenda iCagenda
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 p
CISA
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
cisa·2026-07-10·CVSS 9.8
CVE-2026-48939 [CRITICAL] CWE-434 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Vulnerability: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Affected: iCagenda iCagenda
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence
No detection rules found.
Nuclei
Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE
nuclei·CVSS 9.8
CVE-2026-48939 [CRITICAL] Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE
Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE
iCagenda extension for Joomla contains an unrestricted file upload vulnerability in the file attachment feature, letting attackers upload and execute arbitrary PHP code, exploit requires no special privileges.
Template:
id: CVE-2026-48939
info:
name: Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE
author: 0x_Akoko
severity: critical
description: |
iCagenda extension for Joomla contains an unrestricted file upload vulnerability in the file attachment feature, letting attackers upload and execute arbitrary PHP code, exploit requires no special privileges.
impact: |
Attackers can upload and execute arbitrary PHP code, leading to full server compromise.
remediation: |
Update to the latest version of i
https://www.icagenda.com/https://github.com/Polosss/By-Poloss..-..CVE-2026-48939https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939https://www.icagenda.com/docs/changelog/icagenda-3-9-15https://www.icagenda.com/docs/changelog/icagenda-4-0-8
2026-06-20
Published
2026-07-10
Added to CISA KEV
Exploited in the wild