CVE-2026-48939

CRITICAL KEV NUCLEI

Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-48939 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 10, 2026. EIP tracks 4 public exploits from researchers including ChiefYoru, HORKimhab, shinthink. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets a pre-authentication arbitrary file upload vulnerability in the iCagenda Joomla extension (CVE-2026-48939), allowing remote code execution via crafted PHP file uploads. The PoC includes version detection, multi-threaded exploitation, and webshell deployment with upload capabilities.

Description

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Exploits (4)

github WORKING POC
by ChiefYoru · pythonpoc
https://github.com/ChiefYoru/CVE-2026-48939_PoC

This exploit targets a pre-authentication arbitrary file upload vulnerability in the iCagenda Joomla extension (CVE-2026-48939), allowing remote code execution via crafted PHP file uploads. The PoC includes version detection, multi-threaded exploitation, and webshell deployment with upload capabilities.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: iCagenda Joomla Extension (versions < 3.9.15, 4.0.x < 4.0.8)
No auth needed
Prerequisites: Target must have iCagenda extension installed · Vulnerable version of iCagenda (< 3.9.15 or 4.0.x < 4.0.8) · Writable upload directory in predefined paths
mistral-large-3 · analyzed Jul 19, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/48xxx/CVE-2026-48939.md

The repository contains only a markdown file with a high-level description of CVE-2026-48939, a Joomla iCagenda extension RCE vulnerability, but no technical details or exploit code. It links to external GitHub repos and an encrypted backup, which are red flags for potential social engineering.

Classification
Suspicious 95%
Attack Type
Rce
Complexity
Unknown
Reliability
Unknown
Target: iCagenda extension for Joomla < 4.0.8/3.9.15
No auth needed
Prerequisites: Access to Joomla with vulnerable iCagenda extension
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →
github WORKING POC
by shinthink · pythonremote
https://github.com/shinthink/CVE-2026-48939

This repository contains a functional exploit for CVE-2026-48939, a pre-authentication arbitrary file upload vulnerability in the iCagenda Joomla extension. The exploit uploads a PHP webshell via the registration.submit endpoint, bypassing view-layer access controls, and achieves remote code execution (RCE).

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: iCagenda Joomla Extension versions 3.2.1–3.9.14 and 4.0.0–4.0.7
No auth needed
Prerequisites: Target must have iCagenda Joomla extension installed in a vulnerable version · Web server must allow PHP execution in upload directories
mistral-large-3 · analyzed Jul 06, 2026 Full analysis →
github WORKING POC
by Polosss · poc
https://github.com/Polosss/By-Poloss..-..CVE-2026-48939

The repository provides a functional exploit for CVE-2026-48939, an unauthenticated file upload vulnerability in iCagenda for Joomla, leading to Remote Code Execution (RCE). It includes detailed technical analysis, curl commands, and a PoC script for exploitation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: iCagenda 3.2.1 - 3.9.14 and 4.0.0 - 4.0.7
No auth needed
Prerequisites: Joomla 6 with vulnerable iCagenda version · Access to the target's submission endpoint
mistral-large-3 · analyzed Jun 29, 2026 Full analysis →

Nuclei Templates (1)

Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE
CRITICALVERIFIEDby 0x_Akoko
Shodan: http.html:"com_icagenda"
FOFA: body="com_icagenda"

Scores

CVSS v3 9.8
EPSS 0.8250
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-10
VulnCheck KEV 2026-07-10
ENISA EUVD EUVD-2026-38109
CWE
CWE-434
Status published
Products (4)
icagenda.com/iCagenda extension for Joomla 1.0.0-3.9.14
icagenda.com/iCagenda extension for Joomla 3.2.1-4.0.7
icagenda.com/iCagenda extension for Joomla 4.0.0-4.0.7
joomlic/icagenda 3.2.1 - 3.9.15
Published Jun 20, 2026
KEV Added Jul 10, 2026
Tracked Since Jun 20, 2026