Phoca Downloads Authenticated File Upload Vulnerability (CVE-2026-57828) — High Severity

Understanding the Phoca Downloads Vulnerability

The Phoca Downloads extension for Joomla, a popular tool for managing website downloads, recently addressed a critical security flaw. Versions up to 6.1.2 contained a vulnerability that allowed a logged-in user to upload malicious files, specifically executable PHP scripts, into the public download folder. Once uploaded, these files could be executed by an attacker, leading to what is known as Remote Code Execution (RCE). This means an attacker could potentially take full control of your server.

The good news is that Phoca has released a fix in version 6.1.3. It is crucial for all administrators using Phoca Downloads to update their installations promptly to protect their websites from this serious threat.

CVE Details

This vulnerability is identified as CVE-2026-57828. It was officially published on July 11, 2026, and its status is “Analyzed”.

  • Product: Phoca Downloads for Joomla
  • Published Date: July 11, 2026
  • Severity: HIGH
  • Status: Analyzed

Affected Products

The authenticated arbitrary file upload vulnerability impacts all versions of the Phoca Downloads Joomla extension up to and including version 6.1.2.

Current Status

The vulnerability has been analyzed and a fix is readily available. Phoca released version 6.1.3 on July 10, 2026, which contains the necessary patch to address this security flaw.

Severity Level

This vulnerability carries a HIGH severity rating with a CVSS 4.0 score of 9.0 (Critical). While it leads to Remote Code Execution, which is extremely dangerous, it requires a few specific conditions to be met for an attacker to exploit it:

  • The attacker must have a registered user account on the Joomla site.
  • The Phoca Downloads user-upload feature must be enabled, which is not the default setting.
  • A Phoca Download category must grant upload rights to registered users.

These prerequisites make it less broadly exposed than some other critical vulnerabilities, but if your site allows user uploads through Phoca Downloads, the risk is severe.

Possible Solutions

The primary solution is to update your Phoca Downloads extension to the patched version. Here’s what you need to do:

  • Update to Version 6.1.3 or Later: Immediately update all your Joomla installations running Phoca Downloads to version 6.1.3 or newer. Ensure you are installing the correct version; if your usual update channel still offers 6.1.2, you can find version 6.1.3 on Phoca’s official GitHub releases page.
  • Verify User Upload Settings: If you do not intend for users to upload files, ensure the Phoca Downloads user-upload feature is disabled.
  • Check for Tampering: After updating, it’s vital to check if your site was already compromised. Look in the Phoca Download user-upload folder for any suspicious files, especially those ending in .php. Also, review your Joomla user list for any unrecognized administrator accounts and scan your site for recently modified or unfamiliar PHP files that could indicate a backdoor. Tools like a comprehensive malware scanner can assist in this process.

For large numbers of sites, central management tools can help identify all affected installations and push updates efficiently.

References

  • https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/
  • https://www.phoca.cz/phocadownload
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.