CVE-2026-94131: Acymailing.com Acymailing Extension For Joomla

High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cleared, including files outside the upload folder such as configuration.php.

Affected products

  • Acymailing.com Acymailing Extension For Joomla: version 6.0.0-11.0.5 only

Published 2026-09-26. Last modified 2026-09-29.