PatchSiren cyber security CVE debrief
CVE-2026-67365 icagenda.com CVE debrief
The CVE-2026-67365 record details an unauthenticated SQL injection vulnerability in the Joomla Extension icagenda.com, specifically in versions prior to 4.0.0-4.0.11. This vulnerability is reachable via com_ajax without requiring a session, token, or account, posing a critical risk to affected systems. Administrators and users of Joomla Extension icagenda.com, as well as security teams responsible for vulnerability management and patching, should review and apply vendor remediation. The vulnerability has a CVSS score of 9.2, indicating critical severity. Evidence from official CVE Program record and NIST NVD detail page indicates unauthenticated SQL injection vulnerability in iCagenda < 4.0.0-4.0.11, reachable via com_ajax with no session, token or account.
- Vendor
- icagenda.com
- Product
- iCagenda extension for Joomla
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-14
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-14
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of Joomla Extension icagenda.com, as well as security teams responsible for vulnerability management and patching, should review and apply vendor remediation. This includes reviewing system logs for potential exploitation attempts and ensuring that compensating controls are in place for exposed systems. Security teams should prioritize this vulnerability due to its critical severity and potential for significant impact on affected systems and data confidentiality, integrity, and availability. Additionally, operators of platforms hosting iCagenda and security teams responsible for vulnerability management should take immediate action to mitigate potential risks associated with this vulnerability. This involves verifying system configurations, reviewing access controls, and implementing additional security measures as necessary to protect against potential exploitation. Furthermore, security teams should also consider the potential operational impact of this vulnerability and plan accordingly to minimize disruptions to critical systems and services. This includes coordinating with stakeholders, developing incident response plans, and ensuring that necessary resources are available to respond to potential security incidents. By taking proactive steps to address this vulnerability, organizations can reduce the risk of exploitation and protect their systems and data from potential harm. The vulnerability's critical severity and potential for significant impact necessitate prompt action from all relevant stakeholders to ensure the security and integrity of affected systems and data. Therefore, it is essential that administrators, users, and security teams work together to address this vulnerability and prevent potential security incidents. The CVE record was published on 2026-08-14T20:16:55.850Z and has not been modified since then, emphasizing the need for immediate attention to this critical vulnerability. Security teams should also review the official CVE Program record and NIST NVD detail page for additional information and guidance on addressing this vulnerability. By prioritizing this vulnerability and taking prompt action, organizations
Technical summary
Unauthenticated SQL injection vulnerability in iCagenda < 4.0.0-4.0.11, reachable via com_ajax with no session, token or account. CVSS score of 9.2 indicates critical severity. This vulnerability requires immediate attention due to its critical nature and potential for significant impact.
Defensive priority
Critical vulnerability in Joomla Extension icagenda.com, with CVSS score of 9.2, requires immediate attention.
Recommended defensive actions
- Review and apply vendor remediation for iCagenda vulnerability
- Implement compensating controls to restrict access to com_ajax
- Monitor for suspicious activity related to iCagenda
- Inventory checks for affected iCagenda versions
- Exception tracking for potential vulnerability exploitation
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates unauthenticated SQL injection vulnerability in iCagenda < 4.0.0-4.0.11, reachable via com_ajax with no session, token or account.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-67365 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-67365
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-67365 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67365
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.icagenda.com/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.