icagenda has a security flaw

Published July 10, 2026 CVE-2026-48939

iCagenda's event-planning software has a flaw that lets attackers upload malicious files. Attackers can then run their own code on your server, which can steal data or take control.

Severity
CriticalCVSS 3.1 ยท 9.8
Fix
Fixed in 3.9.15Fix recorded on Aug 26, 2026
Affected versions
3.2.1-4.0.7
Weakness
CWE-434Unrestricted Upload of Dangerous File Type
Exploit likelihood
20% in 30 daysEPSS, higher than 97% of known flaws
Affects
iCagenda extension for Joomla
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Jul 10, 2026
Federal fix deadline
Jul 13, 2026

How it works

Attackers send a malicious file through iCagenda's event attachment feature, bypassing the normal file checks and uploading it directly to your server.

What to do

Check the installed icagenda version. This advisory applies to 3.2.1 to before 3.9.15 or 4.0.0 to before 4.0.8.

Update icagenda to 3.9.15 or 4.0.8 or newer. Then verify the installed version.

Technical details

Affected software: iCagenda extension for Joomlaby icagenda.com

The source identifies icagenda as the affected product. Affected ranges: 3.2.1 to before 3.9.15, 4.0.0 to before 4.0.8. Fixed versions: 3.9.15, 4.0.8.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator