External risk intelligence

Joomla UP Plugin Unauthenticated Remote Code Installation.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-97163

The vulnerability affects a plugin for Joomla, a widely used content management system. Joomla sites are typically deployed as public-facing web applications. Because this extension is integrated into the web application's framework, it is commonly exposed to the internet as part of the public web surface.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a Joomla extension, potentially allowing unauthenticated remote code installation. This issue affects specific versions of the UP plugin from lomart.fr, a component commonly used in Joomla websites. The primary concern is to determine if this extension is in use within our environment and assess any potential exposure.

  • Unauthenticated code installation risk.
  • Confirm use to understand relevance.
  • Assess exposure for potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can remotely execute arbitrary code on a Joomla site by exploiting a vulnerability in the UP plugin extension. This is possible because the plugin is unauthenticated, meaning no login is required to trigger the vulnerability. If successful, an attacker could compromise the entire system.

  • No authentication required to attack.
  • Remote code installation via plugin.
  • Complete system compromise is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to perform remote code installation on a Joomla website when the UP plugin extension is installed. This could impact the integrity and availability of the website and its underlying system.

  • Website code and system integrity at risk.
  • Unauthenticated remote code installation.
  • Compromised website and potential system impact.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a Joomla extension impacts public-facing websites, likely managed by web administrators or platform teams. The first critical step is to identify all instances of the affected Joomla extension, confirm its exposure and business criticality, and then assign ownership for remediation planning.

  • Assign ownership to application or platform teams.
  • Verify internet reachability and business impact.
  • Plan coordinated remediation during maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the lomart.fr UP plugin for Joomla?

The UP plugin is an extension used within the Joomla content management system to add specialized functionality to websites. It integrates directly into the Joomla framework, allowing developers or site administrators to manage specific features. Because it is a plugin, it operates within the context of the larger Joomla application, meaning any security flaws within this component can potentially affect the entire website's environment.

What does unauthenticated remote code installation mean for CVE-2026-97163?

This vulnerability involves improper access control (CWE-284) and potential file path issues (CWE-22). In plain terms, it means the plugin fails to verify who is making a request, allowing an unauthorized person to send commands that the server executes. This grants an attacker the ability to run arbitrary code on the web server without needing a password or administrative access to the Joomla site.

How is this vulnerability triggered?

An attacker triggers this by sending specially crafted network requests directly to the affected Joomla site. Because the plugin lacks authentication, the system processes these commands immediately. Importantly, this bug is not triggered by standard site usage by legitimate visitors; it requires an actor to specifically target the plugin's interaction points to install or execute unauthorized code.

Do I need to worry if my Joomla site uses this plugin?

Yes, this is a significant concern. According to Halo Surface Signal, because the UP plugin integrates into a content management system typically deployed as a public-facing web application, it is likely exposed to the internet. Since the vulnerability is remotely exploitable, any Joomla instance with the affected version installed is considered accessible to external threats by default.

When should I take action for CVE-2026-97163?

You should act immediately by first auditing your Joomla installations to confirm if the UP plugin is present and if it matches the affected version range. Once identified, coordinate with your web administrators to restrict access or apply updates. The priority is to verify if your specific site configuration is reachable from the internet, as this increases the urgency of remediation.

References