CVE-2026-94132
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.
| CWE | CWE-434 |
| Vendor | acymailing.com |
| Product | acymailing enterprise extension for joomla |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for acymailing.com acymailing enterprise extension for joomla
Be the first to know when new unknown vulnerabilities affecting acymailing.com acymailing enterprise extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
acymailing.com / AcyMailing Enterprise extension for Joomla
1.0.0-11.0.5