CVE-2026-67283: Tabaoca.org Cotton Cloud Extension For Joomla

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.

Affected products

  • Tabaoca.org Cotton Cloud Extension For Joomla: version 1.0.0-2.0.1 only

Published 2026-08-12. Last modified 2026-08-26.