
Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness verification.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-77991
JEM - Joomla Event Manager 5.0.0 - joomlaeventmanager.net
I am @abraxas_null. Loopback lab. The client is CVE-2026-77991-Abraxas-Labs.py.
The advisory named a model. Privileged RCE: administrator CSS source manager writes whatever extension you give it, including PHP. JemModelSource::save File::writes jform[source] to media/com_jem/css/<filename>. 5.0.0 resolveSourceFile blocks .. and does not require .css. 5.0.1 adds JemCssFilePolicy::isValidFileName. Unauthenticated POST is not this CVE.
| CVE | CVE-2026-77991 · CVE.org |
| CWE | CWE-434 |
| CVSS | Critical: 9.4 |
| Product | JEM - Joomla Event Manager |
| Affected | all versions through 5.0.0 (inclusive) |
| Patched | 5.0.1 and later |
| Auth | authenticated (administrator) |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Log in as an administrator who can core.edit com_jem. Edit a CSS source whose filename is poc_witness.php. Save echo-only PHP. GET /media/com_jem/css/poc_witness.php. That is code execution as the web user. The CSS manager is not only CSS.
The advisory named the source model. I read save, then resolveSourceFile, then the 5.0.1 policy class. HTTP is com_jem task=source.save, not an ajax action=.
Login. Edit first (source.edit&id= plus base64 of the filename) so session state holds the name. Then save. The save 200 is still tens of kilobytes of administrator HTML. The follow-up GET is seventeen bytes.
Wrong turns: unauthenticated POST; writing a .css file only (intended CSS manager); skipping source.edit and POSTing jform[filename] alone; waiting for tiny JSON (this is not WordPress admin-ajax).
Port 8088. JEM 5.0.0. Administrator admin / lab password. CSRF token from the edit page.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-77991-Abraxas-Labs.py
Witness: GET /media/com_jem/css/poc_witness.php contains POC_WITNESS_77991. CSS-manager HTML without that file is not it.
Ways to lose without learning anything:
.css onlyUpdate JEM to 5.0.1 or newer. Re-run CVE-2026-77991-Abraxas-Labs.py against the patched build: POC_WITNESS_77991 must not appear.
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.