CVE-2026-49049 affects the Helix3 plugin for Joomla, including version 3.1.0 and earlier. The plugin exposes an AJAX handler task that can be reached without authentication and permits arbitrary file deletion, arbitrary JSON file write, and modification of template parameters. The issue appears to stem from insufficient restriction of attacker-controlled file path or file target selection in the AJAX functionality, enabling unauthorized manipulation of files and template configuration through crafted requests.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a small standalone Python 3 repository containing a single executable, helix3.py, a requests-only dependency file, and a README. The script is an operational mass-scanning and file-write tool for the claimed CVE-2026-49049 affecting JoomShaper Helix3 on Joomla. It reads a user-supplied target list, normalizes each target to HTTP when no scheme is provided, and processes up to ten targets concurrently using requests.Session with a browser-like User-Agent. For each of two Joomla com_ajax routes, it first posts a save probe using layoutName=probe_check and considers the endpoint active when the HTTP response is 200 and contains "success". It then sends controlled save requests using several layout-name values, including ../../ and ../../../ traversal forms, and checks whether a corresponding .json file can be fetched from the site root, the Helix3 layouts directory, or tmp. Successful URLs are appended to result.txt. The code is not merely a detector: its save probe itself can create content, and its main path attempts persistent attacker-controlled writes. No executable server-side payload or RCE chain is included; the practical impact implemented here is unauthorized content/file creation where the target handler's path handling permits it. The README inconsistently tells users to execute helix3_scanner.py, while the actual entry point is helix3.py.
This six-file Python/PHP repository is an operational Joomla exploitation suite. CVE-2026-Joomla-Suite.py is the command-line entry point: it accepts one target or a target list, can fingerprint installed extensions, supports concurrent scanning, optional proxying and JSON output, and invokes the modules in joomla_exploits.py. It loads payloads/x7-panel.php and attempts the listed extension-specific CVE modules in sequence or a module selected with --cve. Successful deployments are logged locally in panels_joomla.txt and scan_joomla_live.log. The suite claims seven unauthenticated extension paths and includes an additional credential-dependent CVE-2026-73373/com_media path in code. The PHP payload is a functional web shell rather than a benign proof-of-concept: it exposes unauthenticated command execution, filesystem reconnaissance, and arbitrary file-writing/upload features. The only Python dependency is requests; winrarzips_brand.py provides presentation/banner code. CVE and affected-version claims are repository assertions; only the SP LMS Joomla <5.2.2 condition is explicitly stated in the supplied content.
The repository contains a standalone Python 3 mass-exploitation tool and a README. CVE-2026-49049.py accepts a target-list file, deduplicates entries, and processes them with 50 worker threads and a five-second timeout. For each target it normalizes the scheme, targets Joomla's Helix3 com_ajax endpoint, generates a unique temporary PHP filename, and attempts to use traversal prefixes to write attacker-controlled PHP to an executable location. The embedded payload visibly prints a MataKucing marker and php_uname() output, allowing the tool to establish that the uploaded script executed. It stores normalized successful-path records in results.txt and raw execution output in raw_result.txt. README.md documents the claimed Helix3 arbitrary-file-write-to-RCE chain, operational requirements, mitigation guidance, dependencies, and target-list usage. This is an active exploitation tool rather than a passive detector because it attempts to create and execute PHP files on every supplied target.
This repository is a small standalone Python 2 mass-exploitation scanner for CVE-2026-49049, described as an unauthenticated RCE in the Joomla Helix3 plugin. The repo contains only two files: a README explaining usage and behavior, and the main script cve-2026-49049.py. The script is not just a detector: it actively attempts exploitation. For each supplied target, it normalizes the URL, builds the Joomla com_ajax Helix3 endpoint (/index.php?option=com_ajax&plugin=helix3&format=json), and sends a POST request with data[action]=save, a traversal-based data[layoutName], and attacker-controlled PHP in data[content]. It tries two traversal prefixes (../../../ and ../../../../) to place a randomly named PHP file outside the intended directory. After upload, it performs a GET request to /<random_filename>.php.json on the target. It classifies the result in two ways: 'VULNERABLE' if the marker strings are present and raw PHP tags are absent, indicating server-side execution; or 'RAW PHP' if the marker strings and literal '<?php' are present, indicating the file was written but not executed. This means the tool can confirm both code execution and source disclosure/file write conditions. The embedded PHP payload is more than a benign marker: it prints php_uname() for host fingerprinting and exposes a file-upload form that can be used as a basic web shell/file manager once execution is achieved. Results are written to results.txt for executed payloads and rez.txt for raw PHP cases. The script supports multithreaded scanning with a default of 20 threads, 5-second timeouts, duplicate-target suppression, and randomized filenames based on timestamp plus digits. Overall, the repository's purpose is bulk identification and exploitation of vulnerable Joomla/Helix3 targets, with immediate post-exploitation capability through the uploaded PHP file.
This repository is a Python-based mass scanner and exploit tool for CVE-2026-49049 affecting the JoomShaper Helix3 framework in Joomla. It is not tied to a major exploitation framework; it is a standalone operational scanner/exploit utility. Repository structure is small and focused: scan.py is the CLI entry point; core/engine.py manages multithreaded orchestration, result handling, and output files; core/probe.py contains the vulnerability logic, HTTP interactions, version detection, save/remove/import probing, and webshell drop/RCE verification; core/target.py normalizes target URLs and parses target lists; utils/banner.py prints the console banner. targets.txt is a sample input list, and requirements.txt shows the tool depends on requests and colorama. Main exploit capability: the tool targets the unauthenticated Joomla com_ajax Helix3 handler at /index.php?option=com_ajax&plugin=helix3&format=json. It first fingerprints likely Helix3 installations by requesting templateDetails.xml from several known Helix3 template paths. It parses version strings and treats versions below 3.1.1 as vulnerable or potentially vulnerable. It then probes the exposed Helix3 AJAX actions described in the README: save (arbitrary JSON file write with path traversal), remove (arbitrary file delete), and import (template parameter overwrite in v3.x). In --scan mode, the tool performs read-only detection and reports whether save/remove/import appear accessible and whether the target version is likely vulnerable. In --auto mode, it escalates to exploitation by attempting to write a PHP webshell using traversal-controlled layoutName values and a hardcoded payload <?php system($_GET['cmd']); ?>. The intended outcome is a dropped double-extension file such as up.php.json in a web-accessible location. The tool then sends a GET request with a cmd parameter, typically id by default, and uses response heuristics such as uid=, gid=, www-data, or whoami-like output to confirm successful command execution. It can optionally remove the webshell after verification unless --keep is specified. Notable operational details: the tool supports concurrent scanning with ThreadPoolExecutor, configurable timeout, optional delay between steps, custom User-Agent, HTTP/HTTPS proxying, custom traversal depths, custom webshell name, single-target or file-based target input, plain-text result logging, and optional JSON reporting. The exploit is operational rather than weaponized: it includes a working payload and automation, but the payload is a simple hardcoded PHP command shell rather than a modular framework-integrated payload system. Overall, this repository is a real exploit/scanner implementation whose purpose is to identify vulnerable Helix3 Joomla targets at scale and, in auto mode, verify remote code execution by dropping and invoking a temporary PHP webshell.
Small repository containing a README and a minimal Bash PoC. The exploit targets CVE-2026-49049, described as an unauthenticated arbitrary file write in the JoomShaper Helix3 Joomla plugin via the Joomla com_ajax entry point. The repository structure is simple: README.md provides the vulnerability narrative, affected versions, request anatomy, expected server responses, and mitigation guidance; exploit.sh is the executable PoC. The PoC sends a POST request to a Joomla endpoint with option=com_ajax, plugin=helix3, and format=json, then supplies nested form fields under data[] to invoke action=save. The key capability is path traversal through data[layoutName], allowing the attacker to escape the intended layout directory and cause the plugin to write attacker-controlled content to an arbitrary relative path, with .json appended automatically. The included payload writes a benign probe JSON object, but the README notes real-world abuse could store defacement content or backdoor material. This is a real exploit PoC rather than a detector: it actively attempts file creation on the target. No advanced payload customization or framework integration is present, so maturity is best classified as operational but basic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.