Administrators using the UP (Universal Plugin) for Joomla should urgently identify and update affected releases. Four verified vulnerabilities include unauthenticated arbitrary file access, SQL injection and remote code installation risks, with fixes available in UP 6.1.0 for Joomla 5.2–6.x and UP 5.2.1 for Joomla 3.10–5.1.
Four serious UP plugin vulnerabilities affect Joomla sites running UP versions 5.0.0–5.2.0 or 6.0.0–6.0.29. Three of the issues can be reached without a login, including an arbitrary file access issue and a Critical remote code installation flaw. Site owners should establish their installed UP version, apply the appropriate fixed release, and review their sites for unusual activity.
UP plugin vulnerabilities require prompt action
The UP (Universal Plugin) for Joomla is affected by four distinct, verified security vulnerabilities: CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, and CVE-2026-97163. The affected version ranges are the same for all four issues: UP versions 5.0.0–5.2.0 and 6.0.0–6.0.29.
The immediate priority is to remove affected releases from internet-facing sites. The vendor source identifies UP 6.1.0 as the fixed release for Joomla 5.2–6.x, while sites on Joomla 3.10–5.1 should use UP 5.2.1. Review the UP plugin project source before scheduling the update, particularly where an extension update must be coordinated with a Joomla core upgrade or a staging deployment.
The urgency is driven by both impact and exposure. CVE-2026-97161 and CVE-2026-97163 are unauthenticated, meaning a remote party does not need a Joomla account to reach the vulnerable functionality. That does not establish that a particular site has been attacked, but it does mean patching should not wait for a routine maintenance window.
Verified CVEs, affected versions and severity
The following table summarises the confirmed information. Scores are CVSS 4.0 base scores assigned by the Joomla CNA; they are not CVSS 3.1 scores. Each listed CVE currently has an NVD status of Received, which means NVD has received the record but has not yet completed its full analysis.
| Extension | CVE | Authentication | Issue | Affected UP versions | Recommended version | CVSS 4.0 | CISA KEV status |
|---|---|---|---|---|---|---|---|
| UP plugin for Joomla | CVE-2026-97160 | Required; privileged user | PHP command injection | 5.0.0–5.2.0; 6.0.0–6.0.29 | 6.1.0 for Joomla 5.2–6.x; 5.2.1 for Joomla 3.10–5.1 | 9.4 Critical | Not listed |
| UP plugin for Joomla | CVE-2026-97161 | Not required | Path traversal and arbitrary file access | 5.0.0–5.2.0; 6.0.0–6.0.29 | 6.1.0 for Joomla 5.2–6.x; 5.2.1 for Joomla 3.10–5.1 | 9.2 Critical | Not listed |
| UP plugin for Joomla | CVE-2026-97162 | Not required | SQL injection | 5.0.0–5.2.0; 6.0.0–6.0.29 | 6.1.0 for Joomla 5.2–6.x; 5.2.1 for Joomla 3.10–5.1 | 8.3 High | Not listed |
| UP plugin for Joomla | CVE-2026-97163 | Not required | Remote code installation | 5.0.0–5.2.0; 6.0.0–6.0.29 | 6.1.0 for Joomla 5.2–6.x; 5.2.1 for Joomla 3.10–5.1 | 10.0 Critical | Not listed |
These are separate weaknesses, so installing a vulnerable UP release can expose a site through more than one route. The table should also help agencies identify affected client sites quickly when maintaining an extension inventory.
What the four UP vulnerabilities mean
Unauthenticated file access and remote code installation
CVE-2026-97161 is an unauthenticated path traversal and arbitrary file access issue. The verified description includes arbitrary file reading and file creation through path traversal. In practical terms, a weakness in file-path handling can allow access beyond the files that an externally reachable request should be permitted to use. Depending on the environment and the files involved, unauthorised file access can expose sensitive configuration or application data and can create material operational risk.
CVE-2026-97163 is the most severe issue in the set: an unauthenticated remote code installation vulnerability, rated CVSS 4.0 10.0 Critical. The advisory describes a condition in which a remote party can cause code to be downloaded and installed as executable PHP. Because no Joomla login is required and affected sites may be network reachable, a successful attack could result in a full site compromise. This is why temporary deactivation or access restriction is a reasonable precaution if an immediate upgrade is not possible.
SQL injection and privileged command injection
CVE-2026-97162 is an unauthenticated SQL injection vulnerability rated CVSS 4.0 8.3 High. SQL injection can allow crafted requests to alter how an application interacts with its database, with potential consequences that include exposure or modification of data. Its lower score relative to the other entries does not make it an acceptable residual risk on a public Joomla site.
CVE-2026-97160 is an authenticated PHP command injection vulnerability that requires a logged-in user with sufficient privileges. It is rated CVSS 4.0 9.4 Critical. This is a different exposure model from the unauthenticated flaws, but it reinforces the need to review administrator accounts, avoid unnecessarily broad privileges, and investigate unexpected privileged activity.
Update UP safely and verify the result
Make this a controlled security update, not simply an extension installation. A reliable process reduces the chance that an incomplete upgrade, stale cache, or untested compatibility issue leaves a site exposed or unavailable.
- Inventory every site. Identify whether UP is installed and determine its exact version. Treat versions 5.0.0–5.2.0 and 6.0.0–6.0.29 as affected.
- Choose the correct fixed branch. For Joomla 5.2–6.x, upgrade UP to 6.1.0. For Joomla 3.10–5.1, upgrade UP to 5.2.1. Do not assume a version outside the stated affected ranges is fixed unless supported by current vendor information.
- Protect the site during the change. If patching cannot happen promptly, especially on a public site, consider temporarily disabling UP or restricting public access to its affected functionality. Keep the measure proportionate and test that required site functions remain available.
- Back up before changing production. Take and verify a recoverable backup of site files and the database. Where practical, validate the update in a staging copy first.
- Install and confirm. Complete the extension update using the normal trusted administration process, then confirm the installed UP version and test the Joomla functions that depend on the plugin.
- Record the remediation. Log the sites updated, the previous and installed versions, the date, and any compensating control used while patching was pending.
A web application firewall can be an additional temporary layer for publicly exposed services, but it is not a substitute for replacing an affected extension version. Similarly, a backup helps recovery but does not prevent unauthorised access.
Review for signs that need investigation
There is no authoritative confirmation that these UP vulnerabilities are being exploited in the wild. Nevertheless, the presence of unauthenticated, network-reachable flaws supports a focused post-update review. The goal is to identify anomalies that merit investigation without treating ordinary site activity as proof of compromise.
- Review web server and application logs for unusual requests associated with UP activity, particularly repeated failures, abnormal file-access patterns, or unexpected requests around the period the site ran an affected version.
- Check for unexpected file creation or changes in Joomla directories and other locations where executable PHP should not have appeared through normal administration.
- Review Joomla administrator and other privileged accounts. Confirm that each account is expected, follows least-privilege practice, and has not shown unexplained changes or activity.
- Compare key site files with a known-good backup or approved deployment baseline, and investigate unexplained differences using your established incident-response process.
- Review database and extension activity where logs are available, giving priority to unexpected changes that cannot be tied to authorised administration or deployment work.
If the review identifies credible signs of unauthorised changes, preserve relevant logs and evidence before undertaking broad cleanup work. Then contain the issue, rotate credentials as appropriate, restore trusted files or data where needed, and obtain qualified incident-response assistance if the scope cannot be established internally.
Severity is not the same as confirmed exploitation
The Joomla CNA’s CVSS 4.0 scores explain why these issues deserve rapid remediation: they assess the technical severity and potential impact of a vulnerability. They do not, by themselves, prove that a vulnerability has been used against a particular site or is under active exploitation.
At the time of this advisory, none of CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, or CVE-2026-97163 is listed in the CISA Known Exploited Vulnerabilities catalog. There is also no authoritative confirmation of active exploitation or ransomware use associated with these CVEs. This should be understood as a statement about currently verified evidence, not a reason to delay updates.
All four NVD entries are presently in the Received state, awaiting full NVD analysis. NVD may later add technical detail, configuration information, or its own scoring assessment. Until then, the CVSS 4.0 base scores and vulnerability descriptions supplied by the Joomla CNA are the relevant verified references for prioritisation.
Maintain a practical Joomla extension security routine
This advisory illustrates why extension inventory and patch ownership are essential for Joomla operators. A site cannot be patched promptly if no one knows which extensions are installed, who is responsible for them, or which sites use a shared extension stack.
- Maintain a current register of Joomla core versions, extensions, plugin versions, site owners, and update contacts.
- Define an expedited process for Critical and High extension advisories, including backup, testing, approval, deployment, and post-change verification.
- Use unique, strong administrator credentials and give staff only the permissions needed for their role.
- Keep Joomla core, extensions, templates, PHP, and server software within supported and maintained versions.
- Test backup restoration regularly, because a backup is useful only when recovery has been demonstrated.
- Retain application and web-server logs for a period that supports investigation of security events and update activity.
For agencies, applying these controls across client portfolios is more effective than relying on informal notifications. A version inventory makes it possible to match a future advisory to the exact sites that need attention and to document completed remediation.
Add comment