External risk intelligence

Joomla UP Plugin Path Traversal and File Access Vulnerabilities.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-97161

The vulnerability affects a plugin for Joomla, a widely used content management system. Joomla sites are typically deployed as public-facing web applications, making extensions that handle file access and paths potentially reachable and exposed to the internet in common deployment scenarios.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in a Joomla extension that allows unauthorized access to files and directories. While the specific impact depends on how the extension is used and configured, the underlying issue could enable malicious actors to potentially gain access to sensitive information or compromise system integrity. The main concern is confirming relevance and exposure within your environment.

  • Unrestricted file access in a web extension.
  • Enables potential unauthorized data exposure.
  • Confirm if your Joomla sites are impacted.

Attack Path

How an attacker could exploit the issue

An attacker could potentially reach this vulnerability by interacting with a Joomla website that has the affected UP plugin installed. The plugin's handling of paths and file access, when exposed to the internet, may allow an attacker to traverse directories. Successful traversal could expose sensitive files or lead to other risks.

  • No authentication or privileges are required.
  • The vulnerability is triggered by path traversal.
  • Risk includes unauthorized file access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to read arbitrary files from the server when a specific Joomla extension is present and file access is supported. The exact type of data exposed is not specified, but the attack vector suggests access to files that are normally protected by the system.

  • Arbitrary server files could be read.
  • Exploitation may occur via a vulnerable plugin.
  • Unauthorized information disclosure is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a Joomla plugin impacts application owners and infrastructure teams responsible for web applications. The immediate first step is to identify all instances of the affected plugin, determine their internet reachability and business criticality, and locate the accountable system owner. A risk-based remediation plan, potentially involving vendor coordination, should then be developed.

  • Identify affected plugin instances.
  • Verify internet reachability and criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the lomart.fr UP plugin for Joomla?

The UP plugin is an add-on for the Joomla content management system designed to extend its native capabilities. Extensions like this are frequently used to handle specialized tasks such as file management, directory browsing, or custom data processing, which often requires the software to interact directly with the underlying server's file system.

What does path traversal mean in CVE-2026-97161?

This vulnerability involves Improper Limitation of a Pathname to a Restricted Directory (CWE-22) and Improper Access Control (CWE-284). Essentially, the plugin fails to properly validate input, allowing an attacker to 'traverse' outside of intended folders. This lets them request and potentially read files stored elsewhere on the server that the extension should never have accessed.

How is this Joomla plugin vulnerability triggered?

An attacker triggers this by sending specifically crafted requests to the web server that manipulate file paths. Notably, the vulnerability does not require the attacker to have an account, special privileges, or any prior interaction with the site. If the plugin's file-handling functions are reachable, they can be misused to access restricted system files.

Do I need to worry about this if my site is not public?

According to Halo Surface Signal, this vulnerability is particularly significant because Joomla sites are commonly deployed as internet-facing web applications. If your installation is publicly accessible, it is at higher risk. Internal-only sites may have a smaller attack surface, but they remain vulnerable if an attacker gains access to your internal network.

How should I respond if I use the UP plugin?

Start by auditing your environment to locate every instance where the affected versions of the UP plugin are installed. Once identified, evaluate whether these instances are exposed to the internet and assess the sensitivity of the data on those servers. Consult the vendor for updates and prepare a plan to patch or remove the extension if it is deemed high-risk.

References