External risk intelligence

Joomla UP Plugin PHP Command Injection

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-97160

The vulnerability affects a Joomla plugin, which is a component of a web application. Joomla sites are commonly deployed as internet-facing web services. While the vulnerability requires authentication, the platform itself is typically exposed to the public internet, making the attack surface readily reachable in standard deployment scenarios.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a Joomla extension that could allow authenticated users to execute arbitrary commands on the server. This issue is particularly concerning as it affects a widely used content management system component. The primary focus is on understanding the potential exposure within our environment.

  • An extension flaw allows server command execution.
  • It could impact website integrity and data.
  • Confirm if this extension is in use.

Attack Path

How an attacker could exploit the issue

An attacker with administrative privileges could potentially leverage this vulnerability by submitting specially crafted input through the UP plugin. This input would then be processed by the vulnerable component, leading to the execution of arbitrary commands on the underlying server.

  • Requires authenticated, privileged access.
  • Triggered by submitting malicious input to the UP plugin.
  • Allows arbitrary command execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated, privileged user to execute arbitrary commands on the server when supported by the advisory's conditions. This could affect the integrity and availability of the system and any data it processes.

  • System data and service behavior at risk.
  • Arbitrary command execution via plugin.
  • Potential server compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in a Joomla extension impacts authenticated, privileged users. Owners of web applications utilizing this extension, likely managed by application or platform teams, must first confirm its presence and reachability. Subsequent remediation planning should prioritize business criticality and potential exposure.

  • Application and platform teams own the issue.
  • Verify extension presence and reachability.
  • Plan remediation based on business criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the lomart.fr UP plugin for Joomla?

The UP plugin is an extension for the Joomla content management system, a platform used to build and manage websites. Extensions like this are added to Joomla to introduce specific features or functionality, such as enhanced content control or site management tools, which extend the core capabilities of the base Joomla installation.

What does CWE-94 mean for CVE-2026-97160?

This CVE involves CWE-94, or Improper Control of Generation of Code. In plain English, this means the software incorrectly handles user-supplied data, allowing it to be treated as executable code. Because the plugin does not properly sanitize input, it inadvertently allows an attacker to inject and run their own PHP commands on the host server.

How is this command injection triggered?

An attacker must have authenticated, privileged access to the Joomla site to trigger this flaw. The vulnerability is activated by submitting specially crafted input to the UP plugin. Crucially, this does not occur through normal site navigation or public-facing interactions; it requires an account with administrative-level rights to interact with the vulnerable extension's inputs.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a 'Likely' risk. While the bug requires authenticated access, Joomla sites are typically deployed as internet-facing web services, meaning the attack surface is globally reachable. If your installation is accessible via the internet, the administrative login page—and therefore this plugin—is within reach of potential attackers.

What should I do if I use this Joomla extension?

First, verify if your environment is running the affected versions of the UP plugin (5.0.0-5.2.0 or 6.0.0-6.0.29). If identified, evaluate the plugin's necessity for your site's operations. Coordinate with your platform or web management team to plan for remediation, focusing on protecting the server from unauthorized command execution.

References