Arbitrary file upload in Joomla! - CVE-2026-73373
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unrestricted upload of file with dangerous type in the file upload functionality when uploading SHTML files to a server that executes these files. A remote user can upload a specially crafted SHTML file to execute arbitrary code.
Exploitation depends on the server being configured to execute SHTML files.