Four confirmed Joomla extension vulnerabilities affect OrdaSoft OS Gallery, including its free edition, in versions 1.0.0 through 6.2.6. Site owners should update to OS Gallery 6.2.7 or later, review component permissions, and check for signs of unusual database or file activity.
OrdaSoft’s OS Gallery extension for Joomla, also known as com_osgallery, has four confirmed security vulnerabilities affecting releases from 1.0.0 through 6.2.6. The published CVE records indicate that OS Gallery 6.2.7 is the first fixed version; administrators running an earlier release, including the free edition, should plan an update to 6.2.7 or later as soon as their change process allows.
OS Gallery Joomla Extension Vulnerabilities at a Glance
The four issues are tracked as CVE-2026-88854, CVE-2026-88855, CVE-2026-88856 and CVE-2026-88857. They include two SQL injection vulnerabilities and two remote code execution vulnerabilities. The distinction between them matters: one SQL injection issue is reachable without authentication through the public OS Gallery search module, while the remaining three issues require an authenticated account with core.manage permission on the OS Gallery component.
In Joomla, core.manage is a component-level permission that may be assigned to a gallery manager or another delegated administrative role. It does not necessarily mean that the user is a full Super User. A compromised delegated account can therefore still create a significant risk where this permission is granted unnecessarily.
| Extension | CVE | Authentication | Affected versions | Recommended version | CVSS 4.0 | CISA KEV status |
|---|---|---|---|---|---|---|
| OS Gallery / com_osgallery | CVE-2026-88854 | None | 1.0.0 through 6.2.6 | 6.2.7 or later | 9.3 Critical | Not listed |
| OS Gallery / com_osgallery | CVE-2026-88855 | Authenticated; core.manage |
1.0.0 through 6.2.6 | 6.2.7 or later | 8.6 High | Not listed |
| OS Gallery / com_osgallery | CVE-2026-88856 | Authenticated; core.manage |
1.0.0 through 6.2.6 | 6.2.7 or later | 9.4 Critical | Not listed |
| OS Gallery / com_osgallery | CVE-2026-88857 | Authenticated; core.manage |
1.0.0 through 6.2.6 | 6.2.7 or later | 9.4 Critical | Not listed |
The scores in this table are CVSS 4.0 scores published by the Joomla CNA and reflected in the available CVE and NVD records. They are not CVSS 3.1 scores; CVSS 3.1 scores are not currently provided for these CVEs.
What the Four OS Gallery CVEs Mean
CVE-2026-88854: unauthenticated SQL injection
CVE-2026-88854 is an unauthenticated SQL injection vulnerability in the front-end OS Gallery search functionality, identified as mod_osgallery_search. It affects OS Gallery versions 1.0.0 through 6.2.6 and has a CVSS 4.0 score of 9.3, rated Critical.
Because the affected search feature is public-facing, an anonymous visitor could potentially cause crafted database queries to be processed. SQL injection can expose or alter data held in the Joomla database, depending on the application behaviour and the privileges of the database account. This is the most immediately exposed issue in the group because it does not require a Joomla login.
CVE-2026-88855: privileged SQL injection
CVE-2026-88855 is an SQL injection issue in OS Gallery’s gallery-saving functionality. It has a CVSS 4.0 score of 8.6, rated High. Exploitation requires an authenticated account with core.manage permission on the OS Gallery component.
The required permission reduces exposure compared with the public search issue, but it should not be dismissed. The relevant scenario includes a compromised gallery-manager account, an over-privileged staff account, or a role assigned more access than it needs. Administrators should treat component permissions as part of the remediation, not only as an operational convenience.
CVE-2026-88856 and CVE-2026-88857: privileged remote code execution
CVE-2026-88856 is a remote code execution issue in OS Gallery’s update functionality. CVE-2026-88857 is a remote code execution issue associated with insufficient controls on uploads in watermark-saving functionality. Both affect versions 1.0.0 through 6.2.6, require an authenticated user with core.manage on the component, and have CVSS 4.0 scores of 9.4, rated Critical.
Remote code execution can allow code to run in the web-server context. The practical impact depends on hosting configuration, operating-system controls, file permissions and the privileges available to the web service. This is why a post-update review should include the webroot and relevant upload locations for unexpected executable files or scripts, rather than stopping once the extension update completes.
Who Should Update OS Gallery to 6.2.7
Every Joomla site using OrdaSoft OS Gallery should identify the installed version and edition. The scope includes the free edition. The CVE records describe all versions from 1.0.0 through 6.2.6 as affected, and they indicate version 6.2.7 as the first fixed release. A site already on 6.2.7 or a later version is outside the listed affected range; a site on 6.2.6 or any earlier release should be treated as needing remediation.
For agencies and freelancers, this requires more than checking the current project. Review managed sites, inherited installations, staging copies that may later be promoted, and sites where a client or third party manages extensions. OS Gallery may not be visible on a public page if a gallery is unpublished, but an installed component and its associated modules should still be included in the extension inventory.
Before updating, take and validate a backup according to the organisation’s normal change-control process. Confirm that the backup includes both site files and the database, record the current OS Gallery version, and test the updated gallery, search and media workflows after the maintenance task. Obtain the update from the OrdaSoft source or the established extension update path used by the site.
Prioritised Remediation Checklist
- Find OS Gallery installations. Check every Joomla site, including the free edition, and record the installed version of the OS Gallery component and related modules.
- Update affected versions. If OS Gallery is version 6.2.6 or earlier, update to version 6.2.7 or later. Do not assume an unspecified intermediate release resolves these CVEs.
- Review OS Gallery permissions. Identify users and groups with
core.managefor the OS Gallery component. Retain this permission only for trusted accounts that require gallery-management access. - Check account hygiene. Review gallery-manager and administrator accounts for unexplained access or changes. Where a compromise is suspected, reset relevant credentials and investigate the account before restoring normal access.
- Review logs after patching. Examine web-server, Joomla application and database logs for unusual search activity, abnormal database errors or queries, unexpected uploads, and access patterns that do not fit normal administration.
- Inspect files where appropriate. Because two confirmed issues involve remote code execution, inspect the webroot and OS Gallery-related upload locations for unexpected files or scripts. Preserve relevant evidence before removing files if an incident response investigation is required.
- Reduce future impact. Use a least-privilege database account for Joomla where the hosting architecture permits it, maintain tested backups, and ensure monitoring can alert the team to suspicious authentication, upload or file-change activity.
If an organisation relies on a hosting provider for server administration, provide the provider with the CVE identifiers, the affected version range, and the confirmation that the site has been updated to 6.2.7 or later. Ask whether server logs and file-integrity records are available for the period before remediation. Hosting support can help establish whether follow-up investigation is warranted, but it does not replace reviewing Joomla users, roles and extension configuration.
Severity Scores, NVD Status and Exploitation
Severity scoring and observed exploitation answer different questions. CVSS estimates the potential technical impact and attack conditions of a vulnerability. It does not, by itself, establish that attackers have used the issue against real sites. In this case, the published CVSS 4.0 scores range from 8.6 High to 9.4 Critical, which supports prompt remediation.
At the time of the reviewed evidence, the National Vulnerability Database records for all four CVEs are marked Received. That status means detailed NVD analysis is still pending and may be expanded later. It does not negate the published CVE information or the CVSS 4.0 scores supplied through the Joomla CNA; it means readers should distinguish the CNA-published vulnerability data from completed NVD analysis. The available NVD records include those for CVE-2026-88856 and CVE-2026-88857.
None of CVE-2026-88854, CVE-2026-88855, CVE-2026-88856 or CVE-2026-88857 is listed in CISA’s Known Exploited Vulnerabilities catalog in the reviewed evidence. There is also no authoritative confirmation from CISA or NVD that these vulnerabilities are being exploited in the wild. This should be communicated accurately: the absence of confirmed exploitation is not a reason to defer an update for a publicly exposed SQL injection or for critical flaws reachable by privileged component users.
Practical Follow-Up for Joomla Teams
Once the update is complete, document the version change and permission review in the site’s maintenance record. Confirm that public gallery pages and search functions still behave as expected, and verify that trusted gallery managers can complete their ordinary tasks without broader Joomla privileges being granted as a workaround.
For organisations with multiple people managing content, separate routine content responsibilities from component-management permissions. The three authenticated CVEs show why a role that can manage a specialised component should be assigned deliberately and reviewed periodically. Keep a current list of Joomla extensions, their versions, the business owner for each extension and the account groups authorised to administer them.
The immediate conclusion is straightforward: update affected OS Gallery installations to 6.2.7 or later, reduce unnecessary core.manage access, and perform a proportionate post-update review. These actions address the confirmed vulnerabilities without making unsupported claims about active exploitation or unrelated campaigns.
Add comment