CVE-2026-76611: CWE-22 Improper Limitation of a Pathname to a Restricted Directory in yootheme.com Zoo extension for Joomla
Description
CVE-2026-76611 is a medium severity vulnerability in the yootheme.com Zoo extension for Joomla versions 1.0.0 through 4.1.65. It allows unauthenticated attackers to perform arbitrary directory listing via the Gallery element due to improper limitation of a pathname to a restricted directory (CWE-22). This could expose directory contents without requiring authentication.
CVSS v4.0
Score 6.9medium
Affected software
yootheme.com
Zoo extension for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-76611 affects the Zoo extension for Joomla by yootheme.com. Versions from 1.0.0 up to and including 4.1.65 are vulnerable to an unauthenticated arbitrary directory listing attack through the Gallery element. This is caused by improper limitation of a pathname to a restricted directory (CWE-22), allowing attackers to list directory contents without authentication. The CVSS 4.0 base score is 6.9, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and limited impact on integrity but no impact on confidentiality or availability.
Potential Impact
An unauthenticated attacker can list arbitrary directories on the affected Joomla site running the vulnerable Zoo extension, potentially exposing sensitive directory contents. There is no indication of direct confidentiality, integrity, or availability compromise beyond directory listing. No known exploits are reported in the wild at this time.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider restricting access to the affected Gallery element or disabling it if feasible to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-08-19T14:48:01.169Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8846adacd9273b492312fb
Added to database: 08/21/2026, 12:38:05 UTC
Last enriched: 09/11/2026, 02:48:18 UTC
Last updated: 10/05/2026, 18:48:22 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.