External risk intelligence

Joomla Extension SQL Injection Vulnerability in JCTables Affects Read and Write Queries

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-76570

The vulnerability exists in a Joomla extension's front-end CRUD API controller. Since this component is designed to be accessible via the web front-end and requires no authentication, it is exposed to the public internet by design in normal deployment patterns.

SQL Injection

Joomcode Jc Tables

before 1.21.1

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE describes a critical vulnerability within a Joomla extension that allows unauthenticated users to execute arbitrary SQL commands. This could enable attackers to read or write data directly, potentially leading to unauthorized access or manipulation of sensitive information stored within the Joomla application. The main concern is confirming relevance and exposure to this type of extension.

  • Allows attackers to read or write database data.
  • Matters because it affects public-facing website functions.
  • Confirm if your Joomla sites use this specific extension.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by directly interacting with the extension's front-end API without needing any credentials or authentication. This allows them to manipulate database queries for both reading and writing data.

  • No authentication required for access.
  • Triggered by sending crafted request parameters.
  • Allows unauthenticated database manipulation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to directly manipulate database queries. When supported by the advisory's context, this could affect system data, user data, or sensitive information accessible through the affected Joomla extension.

  • Database integrity and confidentiality.
  • Via unauthenticated, internet-facing API.
  • Compromise of stored information.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical SQL injection vulnerability in joomcode's JC Tables extension affects unauthenticated users and allows data manipulation through the front-end CRUD API. Responsibility for remediation likely falls to the application owners or platform teams managing Joomla sites, with coordination needed for vendor engagement if the extension is sourced externally. The immediate first step is to identify all instances of the affected extension, assess their exposure and business criticality, and then plan remediation based on risk.

  • Identify affected instances and ownership.
  • Verify external reachability and business impact.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the JCTables extension used for in Joomla?

JCTables is a Joomla extension developed by joomcode that provides a CRUD (Create, Read, Update, Delete) API. It is typically used to manage database tables directly from the Joomla interface, allowing users to build and interact with custom data structures within their website's back-end or front-end functionality.

Why is CVE-2026-76570 classified as a SQL injection weakness?

CVE-2026-76570 is a SQL injection (CWE-89) because the extension takes user-supplied input—such as table or column names—and directly inserts them into database queries without proper sanitization. This allows an attacker to manipulate the query logic, enabling unauthorized reading or writing of the underlying database.

How can an attacker trigger this vulnerability?

The vulnerability is triggered by sending crafted network requests to the extension's front-end CRUD API controller. Because the API lacks authentication checks and fails to validate security tokens, no special user privileges or prior access are required to execute the malicious database queries.

Is my Joomla site at risk based on Halo Surface Signal?

Yes, if you use the affected version of JCTables, your site is at significant risk. Halo Surface Signal identifies this as 'Very likely' to be exposed because the vulnerable API controller is designed for public-facing use, meaning it is accessible over the internet by default in most standard Joomla deployments.

What should I do first to address this CVE?

Your first step is to perform an inventory of your Joomla installations to confirm whether JCTables is installed and in use. Once identified, evaluate the criticality of the site and coordinate with your team to apply vendor-provided updates or disable the extension if an update is not immediately available.

References