Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026
Joomla Extension - getk2.org - Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26
CVE-2026-48944
Description
The K2 frontend article-save handler accepts an attachment[N][existing] POST field that is concatenated with JPATH_SITE/ and passed to JFile::copy(). JPath::clean does NOT strip .., and there is no allow-list of source paths. An Author can therefore copy configuration.php (or any other file readable by the web user — including ../../../etc/passwd) into /media/k2/attachments/, then retrieve the contents via the K2 attachment-download endpoint.
Patches
Vulnerability mechanics
References
1- www.getk2.orgmitreproduct
News mentions
0No linked articles in our index yet.