{"id":"CVE-2026-84048","title":"Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attack…","summary":"Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attack…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A","cwe":["CWE-284"],"vendor":"joomgalleryfriends.net","product":"JoomGallery extension for Joomla","affected":["joomgallery_extension_for_joomla 4.0.0-4.4.1"],"published":"2026-09-15","updated":"2026-09-19","sourceUpdated":"2026-09-19T12:16:40.367","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84048","references":[{"url":"https://www.joomgalleryfriends.net/","label":"security@joomla.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T19:38:18.563573Z"},"cvssSource":"cna","epss":0.00311,"epssPercentile":0.24115,"ingestedAt":"2026-09-15T19:42:58.811Z","slug":"CVE-2026-84048","body":"## Overview\n\nJoomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}