2026-09-26 14:14CVE-2026-94131Joomla
PUBLISHED5.2CWE-89

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.

Problem type

Affected products

acymailing.com

AcyMailing extension for Joomla

1.0.0-11.0.5 - AFFECTED

References

GitHub Security Advisories

GHSA-657v-94xx-8q7f

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing...

https://github.com/advisories/GHSA-657v-94xx-8q7f

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-94131
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-94131",
    "assignerOrgId": "6ff30186-7fb7-4ad9-be33-533e7b05e586",
    "assignerShortName": "Joomla",
    "dateUpdated": "2026-09-26T22:57:55.957Z",
    "dateReserved": "2026-09-20T18:03:41.238Z",
    "datePublished": "2026-09-26T14:14:23.396Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "6ff30186-7fb7-4ad9-be33-533e7b05e586",
        "shortName": "Joomla",
        "dateUpdated": "2026-09-26T14:14:23.396Z"
      },
      "title": "Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0",
      "descriptions": [
        {
          "lang": "en",
          "value": "Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "acymailing.com",
          "product": "AcyMailing extension for Joomla",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "1.0.0-11.0.5",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
              "cweId": "CWE-89",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.acymailing.com/",
          "tags": [
            "product"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-09-26T22:57:55.957Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}