---
id: CVE-2026-48939
title: >-
  A vulnerability in the iCagenda extension for Joomla allows the upload of
  arbitrary files in the file attachment feature, ultimately resulting in PHP
  code upload and execution.
summary: >-
  A vulnerability in the iCagenda extension for Joomla allows the upload of
  arbitrary files in the file attachment feature, ultimately resulting in PHP
  code upload and execution.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
  - CWE-434
vendor: joomlic
product: icagenda
affected:
  - 'icagenda >= 3.2.1, < 3.9.15'
  - 'icagenda >= 4.0.0, < 4.0.8'
patched:
  - icagenda 4.0.8
published: '2026-06-20'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48939'
references:
  - url: 'https://www.icagenda.com/'
    label: security@joomla.org
  - url: 'https://github.com/Polosss/By-Poloss..-..CVE-2026-48939'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.icagenda.com/docs/changelog/icagenda-3-9-15'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.icagenda.com/docs/changelog/icagenda-4-0-8'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.20069
epssPercentile: 0.97379
ingestedAt: '2026-07-03T13:02:27.809Z'
kev: true
exploited: true
kevDateAdded: '2026-07-10'
kevDueDate: '2026-07-13'
kevRansomware: false
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/shinthink/CVE-2026-48939'
    - 'https://github.com/Polosss/By-Poloss..-..CVE-2026-48939'
    - 'https://github.com/ChiefYoru/CVE-2026-48939_PoC'
  nuclei:
    - CVE-2026-48939
  checkedAt: '2026-09-21T15:29:15.706Z'
exploitAvailable: true
---

## Overview

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

## Affected

- `icagenda >= 3.2.1, < 3.9.15`
- `icagenda >= 4.0.0, < 4.0.8`

## Remediation

Upgrade past the affected range:

- `icagenda 4.0.8`
