CVE-2026-84048
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 15, 2026
Vendor
unknown
Description
Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.