EIP-2026-108333

PRE-CVE

Joomla! Component com_docman - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108333. PoCs published by Hugo Santiago.

AI-analyzed exploit summary This exploit demonstrates a Full Path Disclosure (FPD) and Local File Disclosure/Include (LFD/LFI) vulnerability in the Joomla docman component. It leverages improper input validation in the 'file' parameter to disclose server paths and read arbitrary files, including sensitive configuration files.

Description

Joomla! Component com_docman - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by Hugo Santiago · textwebappsphp
https://www.exploit-db.com/exploits/37620

This exploit demonstrates a Full Path Disclosure (FPD) and Local File Disclosure/Include (LFD/LFI) vulnerability in the Joomla docman component. It leverages improper input validation in the 'file' parameter to disclose server paths and read arbitrary files, including sensitive configuration files.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Joomla docman component (com_docman)
No auth needed
Prerequisites: Access to the target URL with the vulnerable component
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026