Critical RCE Vulnerability Found in YOOtheme ZOO Plugin CVE-2026-74803

Critical RCE Vulnerability Found in YOOtheme ZOO Plugin

A critical security vulnerability has been uncovered in YOOtheme ZOO, a popular content application builder extension for the Joomla Content Management System (CMS). Tracked as CVE-2026-74803, this vulnerability holds the highest possible severity rating of CVSS 10.0 Critical, exposing affected websites to unauthenticated Remote Code Execution (RCE).

If your website relies on the YOOtheme ZOO extension to manage front-end submissions, user directories, or product catalogs, your server could be at immediate risk of a complete takeover. This deep-dive article explains how the flaw works, who discovered it, and the exact steps you need to take to secure your digital infrastructure.

What is CVE-2026-74803? Understanding the Exploit

The core issue stems from an unauthenticated arbitrary file upload vulnerability within the ZOO (com_zoo) component. Security researcher Phil Taylor from mySites.guru discovered and verified the exploit on live test environments.

How the File Upload Bypass Works

The vulnerability lies specifically within the Image element utilized by ZOO front-end submission forms. When a user uploads a file through this element, the extension behaves insecurely in the following ways:

  • Weak Header Validation: The plugin only checks the client-supplied Content-Type header. It does not perform deep file inspection to ensure the file is a real image.
  • No File Extension Allow-list: There is no strict internal list restricting acceptable file extensions like .jpg or .png.
  • Safe-naming Flaw: The filename passes through Joomla’s standard File::makeSafe function, which sanitizes special characters but explicitly preserves the dangerous .php extension.

Because guest or anonymous access to submission forms is active by default in ZOO—and captcha protections are turned off by default—any visitor can exploit this loophole.

An attacker can easily send a malicious PHP web shell disguised with an image/jpeg content header. The server writes this file directly into the public web root directory at images/zoo/uploads/. Once uploaded, the attacker can navigate directly to the file URL, forcing the web server to execute the code and granting full system access.

Chaining Exploit Risks, SQL Injection & Open Redirects

The investigation into com_zoo revealed that CVE-2026-74803 was not an isolated incident. YOOtheme ZOO versions up to and including 4.1.63 contained two additional serious vulnerabilities that were patched simultaneously:

1. Unauthenticated SQL Injection (CVE-2026-74804)

Holding a critical CVSS 9.3 score, the ItemController::element() function was found to interpolate user request parameters straight into database queries without any escaping or quoting. Attackers can leverage this to bypass access controls, view restricted items, or use UNION statements to steal confidential data directly from your database.

2. Open Redirect (CVE-2026-75114)

Rated as a CVSS 5.1 Medium threat, the CommentController::twitterAuthenticate() failed to validate host targets during redirection. This allows malicious actors to construct phishing links using your trusted domain name to bounce victims to dangerous external sites.

How to Secure Your Joomla Site

Leaving your extension unpatched makes your server an easy target for automated bot scans. Follow this defensive checklist immediately to protect your data.

Step 1: Update to the Safe Version

While YOOtheme addressed the initial three flaws in version 4.1.64, subsequent security gaps were identified and resolved in versions 4.1.65 and 4.1.66.

  • Action: Immediately update YOOtheme ZOO to version 4.1.66 or later. This is the minimum safe version required to block all known entry points discovered during this cycle.

Step 2: Implement Temporary Workarounds

If you cannot run an immediate system update, put these temporary defenses in place right now:

  1. Modify Forms: Open your ZOO front-end submission layouts and completely remove the Image element.
  2. Restrict Form Permissions: Change submission configuration settings so that guest users or anonymous public visitors cannot access or load your forms.

Step 3: Conduct a Post-Incident Forensics Audit

Because CVE-2026-74803 requires zero authentication, any website that was online while running a vulnerable version must be handled as potentially compromised.

  • Scan Directories: Manually inspect your images/zoo/uploads/ directory for any unauthorized files, specifically checking for .php extensions.
  • Review Privileged Accounts: Check your Joomla User Manager setup for any newly created administrator profiles you do not recognize.
  • Rotate Secrets: Reset your Joomla secret keys, clear active user sessions, and change database or administrative credentials to prevent persistent backdoor entry.

Frequently Asked Questions (FAQ)

What makes CVE-2026-74803 a CVSS 10.0 vulnerability?

It receives a perfect 10.0 scale ranking because any anonymous web user can exploit it remotely without needing account credentials, passing a CAPTCHA, or tricking a real user into clicking a link. It provides immediate full execution privileges over the server environment.

Does updating to YOOtheme ZOO 4.1.64 make my site completely safe?

No, version 4.1.64 only corrected the initial batch of findings. Developers had to push out additional security corrections in versions 4.1.65 and 4.1.66 to fully clean the upload paths and resolve validation bugs. You should update directly to version 4.1.66 or higher.

Where do malicious files get stored during an attack?

Exploitation attempts push files directly into the images/zoo/uploads/ path located inside your main web directory root. Administrators should regularly audit this specific storage space for unexpected .php files.

What are the signs that my Joomla site has already been hacked?

Check for unknown administrative accounts within your Joomla database console, unauthorized script modifications under your /images file trees, or suspicious database behavior stemming from SQL injections.

References

Read more CVE , find out and visit my website (Nomatali). Thank you.