DIRAS TAKE
Urgent: treat internet-facing Joomla! sites as high risk because unrestricted SHTML uploads can allow remote code execution without credentials; prioritize mitigation where sites accept file uploads or serve SHTML. Restrict upload endpoints and disable server-side SHTML processing until a vendor fix is available.
What is CVE-2026-73373?
An unauthenticated attacker can upload SHTML files to vulnerable Joomla! CMS installations and cause server-side execution, resulting in full remote code execution (CVE-2026-73373). The flaw affects Joomla! CMS branches 1.0.0 through 5.4.6 and 6.0.0 through 6.1.2, and the Joomla! Framework Filesystem package 1.0.0–3.3.0 and 4.0.0–4.2.0. Exploitation requires the ability to send file uploads to a site that accepts them and runs SHTML on the hosting server; no fixed versions are listed by the vendor in the provided facts. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Joomla! Project Joomla! CMS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Joomla! CMS 1.x | 1.0.0-5.4.6 | |
| Joomla! CMS 6.x | 6.0.0-6.1.2 | |
| Joomla! Framework Filesystem package 1.x | 1.0.0-3.3.0 | |
| Joomla! Framework Filesystem package 4.x | 4.0.0-4.2.0 |
Is CVE-2026-73373 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-73373
- Restrict or disable file upload functionality on exposed Joomla! sites where possible.
- Configure the web server to not process SHTML/SSI files or block .shtml and related extensions at the server or application level.
- Apply vendor guidance and monitor Joomla! security advisories for an official patch; plan for rapid update when a fixed release is published.
- Review upload logs and web server access logs for unexpected SHTML uploads and validate integrity of public-facing sites.
Frequently asked questions
Is CVE-2026-73373 being actively exploited?
There are no public reports of exploitation of CVE-2026-73373 as of 2026-09-29.
Which Joomla! CMS versions are affected by CVE-2026-73373?
Joomla! CMS versions 1.0.0 through 5.4.6 and 6.0.0 through 6.1.2 are listed as affected, along with the Framework Filesystem package versions 1.0.0–3.3.0 and 4.0.0–4.2.0.
Is there a patch for CVE-2026-73373?
No fixed versions are listed in the provided facts; follow Joomla! vendor guidance and prepare to apply a vendor-supplied patch when published.
Does CVE-2026-73373 require authentication?
The issue involves unrestricted file uploads and is described in a way that does not require authentication to upload SHTML, so attacker access to an upload endpoint is sufficient if the server executes SHTML.
References
- nvd.nist.gov/vuln/detail/CVE-2026-73373
- cve.org/CVERecord?id=CVE-2026-73373
- joomla.org
- developer.joomla.org/security-centre/1077-20260810-core-unrestricted-uploads-of-shtml-files.html
- All Joomla! Project CVEs on CVE Radar
- CVEs published in September 2026