CVE-2026-76570 is an unauthenticated SQL injection vulnerability in the JoomCode JCTables Joomla extension. The front-end CRUD controller accepts request-supplied table names, columns, values, index fields, and row identifiers, and incorporates them into database queries without adequate authorization, token validation, or SQL handling. The affected read paths can expose arbitrary Joomla and third-party database tables, while update functionality can modify database values. Unsafe quote handling also permits attacker-controlled input to reach SQL WHERE clauses.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file Python repository is an operational PoC for CVE-2026-76570 affecting Joomcode's JCTables Joomla component before 1.21.1. The main implementation is _engine.py, which normalizes target URLs, fetches exposed component manifests to determine versions, checks for JCTables indicators, and issues unauthenticated requests to the com_jctables front-end JSON API. It attempts direct database-table reads from common prefixed Joomla users tables and extracts identifying user fields and bcrypt-like hashes; it can alternatively prove SQL injection using a true-versus-false getrow condition. poc.py provides an interactive and mass-scanning wrapper with concurrent workers and result files. _lab_test.py implements isolated localhost mock services covering vulnerable direct-read behavior, boolean-SQLi fallback behavior, and patched-version handling. The repository contains no Metasploit, Nuclei, or other recognized exploit-framework module; it is a standalone Python tool. The available code demonstrates data disclosure and injection confirmation, rather than the full write-to-RCE chain referenced in the documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated SQL injection vulnerability in the Joomcode JCTables Joomla extension version 1.21.1. Its front-end CRUD API controller lacks Joomla token validation and authentication checks, permitting attacker-controlled table names, column names, and values to be concatenated into read and write SQL queries.
A critical, remotely exploitable unauthenticated SQL injection vulnerability in the joomcode.com JCTables Joomla extension version 1.21.1. An unauthenticated remote attacker can manipulate request-supplied table names, column names, and values to inject SQL into both read and write queries, potentially enabling unauthorized data disclosure and database modification.
Critical unauthenticated SQL read and arbitrary SQL write vulnerability in the JoomCode JCTables Joomla component. Missing authorization and unsafe escaping allow attackers to read arbitrary Joomla database tables, modify records such as administrator password hashes, and chain the access into authenticated Joomla plugin installation and remote code execution as the web-server user.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.