CVE-2026-21627 is an improper access control issue in the Tassos Framework plugin for Joomla. The vulnerability is rooted in how the plugin handled specific AJAX requests delivered through Joomla’s com_ajax entry point. Under certain conditions, these requests could reach and invoke internal framework functionality without proper restriction. Based on the available information, the flaw appears to stem from insufficient access checks or exposure controls around AJAX-accessible internal methods rather than memory corruption or injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script and a README describing CVE-2026-21627 affecting the Joomla plugin Tassos/Novarain Framework (plg_system_nrframework) versions 4.10.14–6.0.37. Structure & entry point: - CVE-2026-21627.py: main exploit driver (argparse CLI) with modes verify|upload|delete|rce|info. - README.md: vulnerability background, usage examples, detection/remediation guidance. Core vulnerability & exploit flow: - Targets Joomla’s com_ajax endpoint for the nrframework plugin (plugin=nrframework) and the non-admin whitelisted task include (task=include), which routes to ajaxTaskInclude(). - The include handler accepts a user-controlled path parameter using RAW filtering (no sanitization), concatenates path+file+.php, and includes it, then instantiates a user-specified class and calls its onAJAX() method. - The exploit chains this file-inclusion primitive to a known gadget class JFormFieldNRInlineFileUpload (nrinlinefileupload.php) located under plugins/system/nrframework/fields/. Capabilities implemented by the script: - Session/CSRF handling: creates a Joomla session by probing the AJAX endpoint, then re-fetches the homepage to extract a session-bound CSRF token (parsed from the csrf.token JS variable). Uses a requests.Session, optional proxy, optional SSL verification disable, and a fixed User-Agent. - verify mode: attempts to confirm the vulnerability (details truncated in provided content, but described as read-only confirmation). - upload mode: uses the gadget’s upload functionality to write attacker-controlled content (base64-encoded in requests per description) into an attacker-chosen directory (default images). Supports different “shell types” (shtml/csv/txt/html) and custom content. - delete mode (destructive): uses the gadget’s remove functionality (unlink without path validation) to delete an arbitrary file path writable by the web server. - rce mode: attempts an execution chain (upload + trigger). README indicates SSI-based execution via .shtml if server supports SSI; otherwise RCE is not guaranteed. - info mode: includes an arbitrary PHP file (relative to JPATH_SITE) and instantiates a specified class for reconnaissance/behavioral probing. Notable targeting details: - Default SEF prefix is /it/ and the exploit builds URLs as: <target><sef_prefix>component/ajax/ . This is a key operational assumption; users must adjust for sites without that prefix. Overall purpose: - An unauthenticated network exploit for CVE-2026-21627 providing practical post-exploitation primitives (file write and file delete) via a gadget chain, plus an optional RCE attempt dependent on server configuration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.