CVE-2026-65883

CRITICAL

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-65883. PoCs published by shinthink.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-65883, a critical PHP object injection vulnerability in Aimy Captcha-Less Form Guard (Joomla plugin) versions 18.0-20.0. The exploit recovers an XOR keystream from the `clfgd` field, crafts a malicious serialized payload using the FormattedtextLogger gadget chain, and achieves unauthenticated remote code execution via webshell deployment.

Description

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

Exploits (1)

github WORKING POC
by shinthink · pythonpoc
https://github.com/shinthink/CVE-2026-65883

This repository contains a functional exploit for CVE-2026-65883, a critical PHP object injection vulnerability in Aimy Captcha-Less Form Guard (Joomla plugin) versions 18.0-20.0. The exploit recovers an XOR keystream from the `clfgd` field, crafts a malicious serialized payload using the FormattedtextLogger gadget chain, and achieves unauthenticated remote code execution via webshell deployment.

Classification
Working Poc 99%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Aimy Captcha-Less Form Guard (Joomla plugin) 18.0-20.0
No auth needed
Prerequisites: Target must have a vulnerable version (18.0-20.0) of Aimy Captcha-Less Form Guard installed · A captcha-protected form (e.g., registration, login, contact) must be accessible · PHP `unserialize()` must be reachable without allowed_classes restrictions
mistral-large-3 · analyzed Jul 31, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v4 10.0
EPSS 0.0050
EPSS Percentile 40.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
aimy-extensions.com/Aimy Captcha-Less Form Guard plugin for Joomla 18.0-20.0
Published Jul 29, 2026
Tracked Since Jul 29, 2026