• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-48939: pre-auth remote code execution in iCagenda iCagenda

An unauthenticated remote attacker can upload and execute arbitrary PHP on iCagenda, allowing full compromise of affected Joomla sites; this is tracked as CVE-2026-48939. The vulnerability affects iCagenda 3.x releases from 3.2.1 through 4.0.7 and arises from an unrestricted file upload in the attachment feature, requiring only network access to a site running the vulnerable extension.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.20069
CWE
CWE-434
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a July 13, 2026 federal remediation deadline, and no vendor fix is listed — treat exposed installs as high priority to isolate and mitigate immediately.

What is CVE-2026-48939?

An unauthenticated remote attacker can upload and execute arbitrary PHP on iCagenda, allowing full compromise of affected Joomla sites; this is tracked as CVE-2026-48939. The vulnerability affects iCagenda 3.x releases from 3.2.1 through 4.0.7 and arises from an unrestricted file upload in the attachment feature, requiring only network access to a site running the vulnerable extension. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of iCagenda iCagenda are affected?

BRANCHAFFECTEDFIXED
3.x3.2.1-4.0.7

Is CVE-2026-48939 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-10, requiring US federal agencies to remediate by 2026-07-13; public exploit code is also available.

How to fix CVE-2026-48939

  1. Follow vendor guidance and apply any vendor-provided mitigations immediately.
  2. If a patch is unavailable, remove or disable the iCagenda extension from internet-facing Joomla sites.
  3. Restrict access to the site (IP allowlist, web application firewall) and block file upload endpoints.
  4. Monitor web and application logs for suspicious upload activity and signs of PHP webshells.

Frequently asked questions

Is CVE-2026-48939 being actively exploited?

CISA added CVE-2026-48939 to its Known Exploited Vulnerabilities catalog on 2026-07-10 and set a remediation deadline of 2026-07-13; public exploit code is also available.

Which iCagenda versions are affected by CVE-2026-48939?

iCagenda versions 3.2.1 through 4.0.7 (3.x branch) are listed as affected.

Is there a patch for CVE-2026-48939?

No fixed version is listed for CVE-2026-48939 in the available advisory information; follow vendor mitigations or remove the extension until a patch is released.

Does CVE-2026-48939 require authentication?

No; the vulnerability allows unauthenticated file upload and remote code execution on affected iCagenda installations.

References