---
id: CVE-2026-66915
title: >-
  Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An
  unauthenticated attacker could execute arbitrary code by using the ajax_calc
  feature of the calc plugin.
summary: >-
  Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An
  unauthenticated attacker could execute arbitrary code by using the ajax_calc
  feature of the calc plugin.
severity: none
cwe:
  - CWE-94
published: '2026-08-10'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66915'
references:
  - url: 'https://www.fabrikar.com/'
    label: security@joomla.org
  - url: 'https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00823
epssPercentile: 0.55542
ingestedAt: '2026-08-22T15:33:53.578Z'
---

## Overview

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
