CVE-2026-94131: Acymailing.com Acymailing Extension For Joomla
High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.
Affected products
- Acymailing.com Acymailing Extension For Joomla: version 6.0.0-11.0.5 only
Published 2026-09-26. Last modified 2026-09-29.