A critical vulnerability tracked as CVE-2026-65883 affects Aimy Captcha-Less Form Guard for Joomla, enabling unauthenticated PHP object injection through a forged clfgd field in versions 18.0 through 20.0. The flaw stems from the plugin accepting attacker-controlled form data, base64-decoding and XOR-deobfuscating it, and passing the result to PHP unserialize() without integrity protection. The issue is classified as CWE-502 and carries a CVSS v4 rating consistent with network-exploitable, low-complexity attack conditions requiring no privileges or user interaction, with high impact on confidentiality, integrity, and availability.
VulnCheck reported that the bug can be chained to remote code execution as the web user on Joomla 3.9 through 5.2.1 by leveraging the Joomla core FormattedtextLogger gadget, and demonstrated exploitation through a public form flow that recovers the XOR keystream from known plaintext before submitting a crafted serialized object to drop a PHP webshell. Even where direct RCE is not reliable on newer Joomla builds, the vulnerability still allows PHP object injection and complete captcha bypass. Aimy Extensions released a fix in version 20.1, and exposed sites running earlier plugin versions remain at risk until updated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-65883 states that security@joomla.org received the report on July 29, 2026. The issue is a remote code execution vulnerability in the Aimy Captcha-Less Form Guard Joomla plugin caused by PHP object injection via a forged clfgd field.
Aimy Extensions fixed the PHP object injection issue in Aimy Captcha-Less Form Guard by releasing version 20.1. The vulnerable range was versions 18.0 through 20.0.
VulnCheck disclosed that CVE-2026-65883 is a critical unauthenticated PHP object injection flaw in Aimy Captcha-Less Form Guard that can be chained to remote code execution on Joomla 3.9 through 5.2.1 using the Joomla core FormattedtextLogger gadget. The disclosure included technical details showing how attackers could forge the clfgd token and achieve end-to-end exploitation via a public form flow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.