{"cve":{"cve_id":"CVE-2026-48939","is_kev":true,"kev_date_added":"2026-07-10","kev_vendor_project":"iCagenda","kev_product":"iCagenda","kev_vulnerability_name":"iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability","kev_short_description":"iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.","kev_required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due_date":"2026-07-13","kev_known_ransomware":false,"kev_notes":"https://www.icagenda.com/#download ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48939","kev_cwes":["CWE-434"],"epss_score":0.19727,"epss_percentile":0.97201,"epss_as_of":"2026-08-26","description":"A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.","published_at":"2026-06-20T11:56:50.752000Z","last_modified_at":"2026-07-11T05:16:34.140000Z","cvss_v3_score":9.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":10.0,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red","cvss_v4_severity":"CRITICAL","ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":["CWE-434"],"nvd_references":["https://www.icagenda.com/"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-07-11T15:33:43.440151Z"},"effective_severity":"CRITICAL","badges":["kev","poc","news"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"AT","name":"Attack Requirements","value":"N","value_label":"None"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"H","value_label":"High"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"H","value_label":"High"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"H","value_label":"High"},{"metric":"SA","name":"Availability (Subsequent System)","value":"H","value_label":"High"},{"metric":"E","name":"E","value":"A","value_label":"Adjacent"},{"metric":"AU","name":"AU","value":"Y","value_label":"Y"},{"metric":"U","name":"U","value":"Red","value_label":"Red"}]},"affected":[{"vendor_slug":"icagenda.com","vendor_name":"icagenda.com","product_slug":"icagenda-extension-for-joomla","product_name":"iCagenda extension for Joomla","version_start":"3.2.1-4.0.7","version_start_inclusive":true,"version_end":"3.2.1-4.0.7","version_end_inclusive":true,"cpe23_uri":"cve5:icagenda.com:icagenda-extension-for-joomla:3.2.1-4.0.7:3.2.1-4.0.7"},{"vendor_slug":"joomlic","vendor_name":"joomlic","product_slug":"icagenda","product_name":"icagenda","version_start":"3.2.1","version_start_inclusive":true,"version_end":"3.9.15","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\\!:*:*"}],"exploit_refs":[{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-48939.yaml","title":"Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCE","author":"0x_Akoko","disclosed_at":null}],"news":[{"id":540,"source":"The Hacker News","url":"https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html","title":"iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.\n\nThe vulnerabilities, both rated 10.0 on the CVSS scoring system, are below -\n\n\n  CVE-2026-48939 - A vulnerability in the","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8FM8eXCuapKSUef3nzFlgzqlX4a5mJChM9YqCdHOi6QybQ8AM1xbM9NNTyAjS3iyz7iAX6vC8QVHl5zFlAgNyBIgm5FHgFkEGzOg5l3ZXNXI8ILA2GIGKtvYDuy-qpXmfeMHYxheps3XuPCtgedFa9vcimwad9kBjpbF0SEhhxpZoWsWybn0zcgNtppI/s1600/cisa-joomla.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-07-13T05:36:02Z","fetched_at":"2026-07-13T07:16:21.283035Z","trending_score":1.8602728638488664e-7,"cve_ids":["CVE-2026-48939"]}],"references":[{"url":"https://www.icagenda.com/","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-06-20T11:56:50.752000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:55:03.830140Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:55:03.830140Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:55:03.830140Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T23:46:59.033383Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-07-01T07:22:05.035433Z","label":"CVSS score revised","source":"nvd"},{"type":"cvss_changed","at":"2026-07-01T07:22:05.035433Z","label":"CVSS score revised","source":"nvd"},{"type":"cvss_changed","at":"2026-07-01T07:22:05.035433Z","label":"CVSS score revised","source":"nvd"},{"type":"ssvc_changed","at":"2026-07-02T17:35:23.771986Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cisa_reported","at":"2026-07-10T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-07-10T18:34:20.778996Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"first_article","at":"2026-07-13T05:36:02Z","label":"First news coverage","source":"The Hacker News"},{"type":"poc_available","at":"2026-08-06T17:39:38.298696Z","label":"Public PoC available","source":"nuclei"}]}