A critical RSFiles file upload vulnerability in the RSFiles! plugin for Joomla, now documented as CVE-2026-57827 , allows attackers to upload files without authentication and lead to full remote code execution (RCE). According to technical analysis by mySites.guru , the issue was fixed in version 1.17.12 and administrators are urged to upgrade immediately.

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) and, as reflected in the CVE Feed, has been rated CRITICAL with CVSS 4.0 and exploitation conditions that do not require privileges (PR:N) or user interaction (UI:N).
See also: iCagenda: Critical RCE vulnerability exploited on Joomla sites worldwide
RSFiles file upload: how the attack works
In practice, the issue is related to a “frontend upload” path of the com_rsfiles, which could be accessed anonymously. The analysis states that the method that ultimately writes the file to disk did not apply permission checks and did not sufficiently restrict file types/extensions, while the target file name could be passed directly from the request. This opens the way for uploading executable files and then executing them over the web.
The vulnerability is increased because, in typical installations, the downloads folder is located within the web root. Additionally, .htaccess that would prevent PHP from executing in this directory is listed as an optional administrative setting and is not enabled by default, which can make exploitation particularly straightforward on poorly hardened installations.

Impacts and indications of a breach
A successful exploit gives practically full control over the site: access to sensitive files such as configuration.php (and therefore to the database credentials), the ability to create a hidden Super User, a backdoor installation that can survive a simple upgrade of the extension, and possible "movement" to other sites on the same hosting account. For this reason, the SecNews technical team considers it crucial to check, in addition to the upgrade, whether there are traces of a previous exploit.
For example, administrators should check the downloads folder for unexpected files (especially with extensions that should not be there), look for changes to PHP files, and confirm that no new administrative accounts have been created without approval.
See also: CVE-2026-48939: Critical vulnerability in iCagenda (Joomla) with active exploitation

What you should do immediately
The basic recommendation is clear: upgrade RSFiles! to 1.17.12 or later, as checks have been added there (such as valid CSRF token, permissions checks and allow-list before writing the file) that close the anonymous upload feature. If for any reason the upgrade is not immediately possible, consider temporarily withdrawing/disabling the frontend functionality of RSFiles! (e.g. by removing menu items that expose the upload) until the patch is applied.
At the same time, a WAF solution can help reduce risk, but it is not a substitute for installing the update. For more technical details, administrators can refer to the mySites.guru and the official product page on RSJoomla.
It is also worth noting that, although no public PoC has been published, the nature of the flaw (anonymous upload of an executable file) means that the exploit can be easily automated by attackers mass-scanning for exposed pages. Thus, organizations hosting multiple Joomla sites or using shared hosting should treat the update as a priority, monitor logs for suspicious uploads, and confirm that there are no unexpected files in the downloads directory.
The SecNews technical team reminds that timely application of updates to third-party extensions is one of the most effective measures to prevent RCE incidents in CMS installations, especially when they concern upload mechanisms and access to files within the web root.
For those looking to further mitigate the risk, it makes sense to check if the downloads directory is protected by settings that disable script execution, restrict write permissions where possible, and implement monitoring for new file uploads. In any case, the RSFiles file upload remains a "high-risk point" when exposed online, which is why the update to 1.17.12 should be considered a necessary and not an optional hardening move.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
