CVE-2026-94132 is an unrestricted file upload vulnerability in the mailbox-action feature of AcyMailing Enterprise for Joomla before version 11.1.0. The feature saves MIME parts from email received by a monitored mailbox into a web-accessible upload location without validating file extensions. An unauthenticated attacker able to submit email to that mailbox can cause a PHP payload to be written to the Joomla web root and subsequently executed by the web server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file Python repository is a proof-of-concept helper for CVE-2026-94132, an unrestricted file upload/RCE condition asserted to affect AcyMailing Enterprise for Joomla through version 11.0.5. Its sole code file, poc.py, uses requests and urllib3 to normalize supplied target URLs, fingerprint AcyMailing through component XML/CSS paths, parse version information, assess whether the target is below 11.1.0, and probe the web-accessible /media/com_acym/upload/ directory. Optional upload-directory parsing extracts links to potentially executable extensions including .php, .phtml, .phar, .php5, .php7, and .htm. It supports a single target or concurrent check-only processing of a target list, optional proxying, disabled TLS certificate verification, JSON/JSONL reporting, and hit-list output. The exploit chain relies on a separate manual step: an authorized operator emails a PHP attachment to the AcyMailing POP3-monitored mailbox, after which the tool derives or accepts a URL and checks it for the POCBIT-94132-OK marker. Therefore, the repository does not independently deliver email, write files to the target, or provide an interactive shell; it is primarily a detection and post-delivery verification PoC for the documented upload-to-RCE path. Supporting files are README.md documentation, requirements.txt, a sample targets file, license, and git ignore rules.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in the mailbox action feature of AcyMailing Enterprise versions prior to 11.1.0. Incoming email MIME parts were written into a web-accessible upload directory without extension validation, enabling an attacker able to send email to the monitored mailbox to upload a PHP file to the web root and potentially execute it.
A remote code execution vulnerability in the mailbox action feature of AcyMailing Enterprise versions earlier than 11.1.0. Incoming email MIME parts were written to a web-accessible upload path without extension validation, allowing an attacker able to send email to the monitored mailbox to upload a PHP file into the web root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.