HomeSecurityJoomla RSFiles: critical file upload vulnerability leads to RCE (CVE-2026-57827)

Joomla RSFiles: critical file upload vulnerability leads to RCE (CVE-2026-57827)

A critical RSFiles file upload vulnerability in the RSFiles! plugin for Joomla, now documented as CVE-2026-57827 , allows attackers to upload files without authentication and lead to full remote code execution (RCE). According to technical analysis by mySites.guru , the issue was fixed in version 1.17.12 and administrators are urged to upgrade immediately.

RSFiles file upload in Joomla without authentication

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) and, as reflected in the CVE Feed, has been rated CRITICAL with CVSS 4.0 and exploitation conditions that do not require privileges (PR:N) or user interaction (UI:N).

See also: iCagenda: Critical RCE vulnerability exploited on Joomla sites worldwide

RSFiles file upload: how the attack works

In practice, the issue is related to a “frontend upload” path of the com_rsfiles, which could be accessed anonymously. The analysis states that the method that ultimately writes the file to disk did not apply permission checks and did not sufficiently restrict file types/extensions, while the target file name could be passed directly from the request. This opens the way for uploading executable files and then executing them over the web.

The vulnerability is increased because, in typical installations, the downloads folder is located within the web root. Additionally, .htaccess that would prevent PHP from executing in this directory is listed as an optional administrative setting and is not enabled by default, which can make exploitation particularly straightforward on poorly hardened installations.

Critical RSFiles vulnerability in Joomla sites

Impacts and indications of a breach

A successful exploit gives practically full control over the site: access to sensitive files such as configuration.php (and therefore to the database credentials), the ability to create a hidden Super User, a backdoor installation that can survive a simple upgrade of the extension, and possible "movement" to other sites on the same hosting account. For this reason, the SecNews technical team considers it crucial to check, in addition to the upgrade, whether there are traces of a previous exploit.

For example, administrators should check the downloads folder for unexpected files (especially with extensions that should not be there), look for changes to PHP files, and confirm that no new administrative accounts have been created without approval.

See also: CVE-2026-48939: Critical vulnerability in iCagenda (Joomla) with active exploitation

File upload exploit leads to RCE via RSFiles

What you should do immediately

The basic recommendation is clear: upgrade RSFiles! to 1.17.12 or later, as checks have been added there (such as valid CSRF token, permissions checks and allow-list before writing the file) that close the anonymous upload feature. If for any reason the upgrade is not immediately possible, consider temporarily withdrawing/disabling the frontend functionality of RSFiles! (e.g. by removing menu items that expose the upload) until the patch is applied.

At the same time, a WAF solution can help reduce risk, but it is not a substitute for installing the update. For more technical details, administrators can refer to the mySites.guru and the official product page on RSJoomla.

It is also worth noting that, although no public PoC has been published, the nature of the flaw (anonymous upload of an executable file) means that the exploit can be easily automated by attackers mass-scanning for exposed pages. Thus, organizations hosting multiple Joomla sites or using shared hosting should treat the update as a priority, monitor logs for suspicious uploads, and confirm that there are no unexpected files in the downloads directory.

The SecNews technical team reminds that timely application of updates to third-party extensions is one of the most effective measures to prevent RCE incidents in CMS installations, especially when they concern upload mechanisms and access to files within the web root.

For those looking to further mitigate the risk, it makes sense to check if the downloads directory is protected by settings that disable script execution, restrict write permissions where possible, and implement monitoring for new file uploads. In any case, the RSFiles file upload remains a "high-risk point" when exposed online, which is why the update to 1.17.12 should be considered a necessary and not an optional hardening move.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS