CVE-2026-56292 is a SQL injection vulnerability in the AcyMailing component for Joomla versions earlier than 10.11.1. Insufficient handling of attacker-controlled SQL input permits remote exploitation against an affected AcyMailing deployment, enabling unauthorized interaction with its backing database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a focused Python proof-of-concept and mass scanner for CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla. The repo is small and purpose-built: one executable Python script (`cve_2026_56292_acymailing_sqli.py`), documentation (`README.md`, `TECHNICAL.md`), dependency list, and a `dorks.txt` file for target discovery. The main exploit capability is remote unauthenticated web exploitation of the AcyMailing front-end task `frontentityselect::loadEntityFront` via the `columns` parameter. The script constructs requests to `index.php?option=com_acym&ctrl=frontentityselect&task=loadEntityFront&entity=user&offset=0&perCalls=1&columns=...` and injects the SQL payload `id FROM #__acym_user AS user UNION SELECT version()#`. Its goal is not code execution, but confirmation of SQL injection by forcing the application to return the database server version from `version()`. Operationally, the script supports both single-target and multi-target scanning. It uses `requests` with retry logic, optional proxy support, disabled TLS verification, configurable timeout, and concurrent threading for mass scans. Response handling classifies targets into vulnerable, patched, safe, redirect, or error states. Patched detection relies on strings such as `not secured`, `acym_access_denied`, or `injection denied`, while vulnerable detection parses the returned JSON-like `elements` structure and extracts a non-numeric `id` value as the injected database version. The exploit is best characterized as an operational scanner/validator rather than a full post-exploitation tool. It provides actionable output by printing vulnerable targets and optionally writing vulnerable, patched, and error target lists to files. No destructive behavior, persistence, or secondary payload delivery is present. The included markdown files explain the vulnerable code path and patch behavior, and `dorks.txt` contains search-engine queries useful for identifying exposed AcyMailing installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only identifies CVE-2026-56292 in the context of adding a template; it provides no technical details about the vulnerability, affected product, impact, exploitability, or remediation.
A critical SQL injection vulnerability in the AcyMailing component for Joomla affecting versions earlier than 10.11.1, which can allow unauthorized database access and data leakage.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.