External risk intelligence

AcyMailing Enterprise Remote Code Execution Via Unchecked File Uploads

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-94132

The vulnerability affects a Joomla extension designed to process incoming emails for marketing automation. Since these extensions are typically configured to monitor public-facing mailboxes or interact with web-accessible interfaces to handle incoming communication, the attack surface is commonly exposed to external inputs and reachable via internet-based mail traffic.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical remote code execution vulnerability within the AcyMailing Enterprise extension for Joomla. The flaw allows an attacker to upload and execute arbitrary PHP files by exploiting how the extension handles incoming email attachments, potentially leading to a full compromise of the affected website.

  • Malicious file uploads can take over websites.
  • Confirms exposure of an external-facing marketing tool.
  • Assess impact on customer-facing web infrastructure.

Attack Path

How an attacker could exploit the issue

An attacker could send specially crafted emails to a monitored mailbox, which the AcyMailing extension then processes. Because the extension does not properly check the file type of attachments or parts of incoming emails, these could be saved as executable PHP files in the web server's document root. This could allow an attacker to execute arbitrary code on the server.

  • Attacker sends malicious emails to a monitored mailbox.
  • Vulnerable extension saves MIME parts without extension checks.
  • Allows arbitrary code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on the server when the acymailing.com extension is configured to process emails from a monitored mailbox. The vulnerability occurs because the extension does not properly validate file extensions when saving MIME parts of incoming emails, enabling the attacker to upload a PHP file to the web root.

  • Web server file system integrity.
  • Email processing features.
  • Remote code execution on the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Joomla Extension for AcyMailing Enterprise, specifically its mailbox action feature, presents a critical remote code execution risk. This vulnerability allows unauthenticated attackers to upload arbitrary PHP files to the web root by sending specially crafted emails to a monitored mailbox. Ownership will likely fall to the platform or web application team responsible for managing Joomla and its extensions, in coordination with the security team for exposure assessment and the vendor for remediation guidance. The first practical step is to identify all instances of the affected extension, determine their internet reachability, and assess their business criticality to prioritize remediation efforts.

  • Application owners must identify affected instances.
  • Verify internet exposure and business criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is AcyMailing Enterprise and how does it function?

AcyMailing Enterprise is a marketing automation extension for the Joomla content management system. It is commonly used by website administrators to manage email newsletters, subscriber lists, and automated communication campaigns. A core feature of this extension involves monitoring specific email mailboxes to process incoming messages or automate subscription tasks directly through the Joomla platform.

What does CWE-434 mean regarding CVE-2026-94132?

CWE-434 refers to 'Unrestricted Upload of File with Dangerous Type.' In the context of CVE-2026-94132, this means the software fails to properly verify or filter the file types being uploaded to the server. Because the extension does not check incoming email attachments, it allows attackers to save files with executable extensions—like .php—directly into the web root, where the server might then run that code.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted email containing a malicious attachment to a mailbox monitored by the AcyMailing extension. The vulnerability is tied specifically to this email-processing workflow. It is not triggered by standard web browsing or routine site interactions; it requires the extension to be actively configured to ingest and save attachments from the monitored email account.

Is my Joomla site at risk if I use this extension?

According to Halo Surface Signal, this vulnerability is classified as external because the extension is designed to process incoming mail, making it accessible via internet-based traffic. If your instance is configured to monitor a mailbox, it is potentially reachable by external actors. You should prioritize assessing your site if the extension is active and processing email attachments.

What are the first steps to address this CVE?

Begin by identifying all Joomla installations running the AcyMailing Enterprise extension to determine your total footprint. Once identified, verify if the mailbox processing feature is enabled, as this is the primary vector. Coordinate with your platform or web management team to confirm your version status and follow official vendor guidance to apply the necessary updates or security patches for your specific environment.

References