CVE-2026-57827
CRITICALJoomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
Title source: cnaExploitation Summary
EIP tracks 2 public exploits for CVE-2026-57827. PoCs published by Candisexterior171, shinthink.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-57827, an unauthenticated arbitrary file upload vulnerability in RSFiles! Joomla component (< 1.17.12). The exploit bypasses pre-flight checks by directly calling the unguarded `rsfiles.upload` task, allowing PHP shell upload to web-accessible directories for RCE.
Description
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Exploits (2)
This repository contains a functional exploit for CVE-2026-57827, an unauthenticated arbitrary file upload vulnerability in RSFiles! Joomla component (< 1.17.12). The exploit bypasses pre-flight checks by directly calling the unguarded `rsfiles.upload` task, allowing PHP shell upload to web-accessible directories for RCE.
This repository contains a functional exploit for CVE-2026-57827, a critical unauthenticated file upload vulnerability in RSFiles! Joomla component (<1.17.12). The exploit bypasses the split-controller design flaw by directly calling the unguarded write task (rsfiles.upload), allowing arbitrary PHP file upload to web-accessible directories for RCE.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H