CVE-2026-94132: CWE-434 Unrestricted Upload of File with Dangerous Type in acymailing.com AcyMailing Enterprise extension for Joomla
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.
AI Analysis
Technical Summary
CVE-2026-94132 is a CWE-434 vulnerability in the AcyMailing Enterprise extension for Joomla (versions 1.0.0 to 11.0.5). The mailbox action feature improperly handles MIME parts of incoming emails by saving them to the media/com_acym/upload/ directory without validating file extensions. This lack of restriction allows an attacker with the ability to send emails to the monitored mailbox to upload PHP files into the web root, enabling remote code execution.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the affected server by uploading malicious files via email. This can lead to full system compromise, data theft, or service disruption.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the monitored mailbox and implement email filtering to block malicious attachments.
CVE-2026-94132: CWE-434 Unrestricted Upload of File with Dangerous Type in acymailing.com AcyMailing Enterprise extension for Joomla
Description
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.
CVSS v4.0
Score 9.5critical
Affected software
acymailing.com
AcyMailing Enterprise extension for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94132 is a CWE-434 vulnerability in the AcyMailing Enterprise extension for Joomla (versions 1.0.0 to 11.0.5). The mailbox action feature improperly handles MIME parts of incoming emails by saving them to the media/com_acym/upload/ directory without validating file extensions. This lack of restriction allows an attacker with the ability to send emails to the monitored mailbox to upload PHP files into the web root, enabling remote code execution.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary PHP code on the affected server by uploading malicious files via email. This can lead to full system compromise, data theft, or service disruption.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the monitored mailbox and implement email filtering to block malicious attachments.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-09-20T18:03:41.238Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab84f43f7a7c54106d543a7
Added to database: 09/26/2026, 23:03:31 UTC
Last enriched: 09/26/2026, 23:17:40 UTC
Last updated: 09/27/2026, 04:31:22 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.