CVE-2026-48939
CRITICAL KEV NUCLEIJoomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
Title source: cnaExploitation Summary
CVE-2026-48939 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 10, 2026. EIP tracks 4 public exploits from researchers including ChiefYoru, HORKimhab, shinthink. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit targets a pre-authentication arbitrary file upload vulnerability in the iCagenda Joomla extension (CVE-2026-48939), allowing remote code execution via crafted PHP file uploads. The PoC includes version detection, multi-threaded exploitation, and webshell deployment with upload capabilities.
Description
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Exploits (4)
This exploit targets a pre-authentication arbitrary file upload vulnerability in the iCagenda Joomla extension (CVE-2026-48939), allowing remote code execution via crafted PHP file uploads. The PoC includes version detection, multi-threaded exploitation, and webshell deployment with upload capabilities.
The repository contains only a markdown file with a high-level description of CVE-2026-48939, a Joomla iCagenda extension RCE vulnerability, but no technical details or exploit code. It links to external GitHub repos and an encrypted backup, which are red flags for potential social engineering.
This repository contains a functional exploit for CVE-2026-48939, a pre-authentication arbitrary file upload vulnerability in the iCagenda Joomla extension. The exploit uploads a PHP webshell via the registration.submit endpoint, bypassing view-layer access controls, and achieves remote code execution (RCE).
The repository provides a functional exploit for CVE-2026-48939, an unauthenticated file upload vulnerability in iCagenda for Joomla, leading to Remote Code Execution (RCE). It includes detailed technical analysis, curl commands, and a PoC script for exploitation.
Nuclei Templates (1)
http.html:"com_icagenda"
body="com_icagenda"
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H