{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/up-universal-plugin-5.0.0-5.2.0-6.0.0-6.0.29/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lomart:up_plugin:*:*:*:*:*:joomla:*:*"],"_cs_cves":[{"id":"CVE-2026-97163"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["UP (Universal Plugin) (5.0.0-5.2.0, 6.0.0-6.0.29)"],"_cs_severities":["critical"],"_cs_tags":["web-application","rce","joomla","critical-vulnerability"],"_cs_type":"advisory","_cs_vendors":["lomart"],"content_html":"\u003cp\u003eThe UP (Universal Plugin) for Joomla, developed by lomart.fr, contains a critical vulnerability (CVE-2026-97163) allowing unauthenticated remote code execution. The vulnerability exists in the plugin's \u0026quot;mini\u0026quot; package, which features an on-demand download mechanism for action code hosted on GitHub. During this process, the plugin fetches and unpacks remote ZIP archives into \u003ccode\u003eplugins/content/up/actions/\u003c/code\u003e, where the PHP code is subsequently executed by the Joomla framework.\u003c/p\u003e\n\u003cp\u003eCrucially, the plugin implementation fails to perform TLS certificate verification during these GitHub requests, and it lacks sufficient authorization controls for the installation trigger. This allows a network-positioned attacker (performing a Man-in-the-Middle attack) to intercept the request and inject a malicious archive. Exploitation results in the installation of arbitrary PHP code. The vulnerability impacts UP versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29. Security patches have been released in versions 5.2.1 and 6.1.0, which enforce authorization and restore TLS verification.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify Joomla instances running the vulnerable UP plugin using indicators like \u003ccode\u003eplugins/content/up/actions/\u003c/code\u003e in HTTP traffic.\u003c/li\u003e\n\u003cli\u003eAttacker positions themselves as a Man-in-the-Middle between the target Joomla server and GitHub (e.g., via DNS spoofing or BGP hijacking).\u003c/li\u003e\n\u003cli\u003eAttacker triggers the plugin's on-demand action installation by sending an unauthenticated request to a component or endpoint that invokes the \u003ccode\u003eup\u003c/code\u003e plugin action loader.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin initiates a request to the attacker-controlled or spoofed GitHub URL to download an action pack.\u003c/li\u003e\n\u003cli\u003eDue to the lack of TLS certificate validation, the plugin accepts a malicious ZIP archive provided by the attacker.\u003c/li\u003e\n\u003cli\u003eThe plugin automatically extracts the contents of the malicious archive into the \u003ccode\u003eplugins/content/up/actions/\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the newly installed malicious PHP code by navigating to the corresponding plugin action path on the Joomla server.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: remote code execution under the privileges of the web server user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the underlying web server, potentially leading to total system compromise, data exfiltration, and lateral movement within the hosting infrastructure. The vulnerability is rated with a CVSS 4.0 score of 10.0, indicating the highest level of severity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Joomla UP plugin to version 5.2.1 or 6.1.0 immediately to enforce authorization and secure the fetch mechanism.\u003c/li\u003e\n\u003cli\u003eImplement the Sigma rule provided below to detect anomalous web requests targeting the UP plugin's installation or rendering endpoints.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003eplugins/content/up/actions/\u003c/code\u003e directory for any unexpected files or folders that were not part of the legitimate plugin deployment.\u003c/li\u003e\n\u003cli\u003eDeploy network-layer inspection to identify unexpected outbound traffic from web servers targeting GitHub or unknown domains when initiated by the web application process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T21:45:01Z","date_published":"2026-09-26T21:45:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-joomla-up-plugin-rce/","summary":"The Joomla UP plugin (Universal Plugin) is vulnerable to unauthenticated remote code execution via insecure GitHub action installation (CVE-2026-97163), allowing attackers to force the download of arbitrary code due to disabled TLS certificate verification.","title":"Unauthenticated Remote Code Execution in Joomla UP Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-joomla-up-plugin-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - UP (Universal Plugin) (5.0.0-5.2.0, 6.0.0-6.0.29)","version":"https://jsonfeed.org/version/1.1"}