AcyMailing for Joomla lets anyone email their way to RCE
The mailbox monitoring feature in AcyMailing Enterprise saves email attachments straight into the web root without checking their extension. Fixed in 11.1.0.
AcyMailing Enterprise, a paid email marketing extension for Joomla, disclosed a critical remote code execution bug on 26 September. It’s fixed in 11.1.0; every version from 1.0.0 through 11.0.5 is affected.
CVE-2026-94132 (CVSS 9.5) sits in AcyMailing’s mailbox monitoring feature, which polls a POP3 inbox and acts on incoming mail, useful for catching bounces and replies automatically. When a message arrives with an attachment, AcyMailing saves it straight into media/com_acym/upload/, a folder inside the public web root, without checking the file’s extension. Email that inbox a PHP file disguised as an attachment, and the extension responds by writing it to a location the web server will happily execute. No login to the site is needed, only the ability to send mail to whatever address AcyMailing is watching.
Why it matters: this is the same failure mode as the Adminer BOM bug and the Contact Form 7 upload flaw covered here recently, a feature that accepts a file and never checks what kind of file it is. If a client site runs AcyMailing’s mailbox actions, update to 11.1.0 now. The advisory also suggests switching to IMAP or disabling POP3 attachment handling as a stopgap.
The caveat: the attacker needs to know or guess the monitored mailbox address. That address is often the site’s own support or bounce inbox, not a secret, so treat this as practically reachable rather than theoretical.