Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-63047 represents a critical access control failure in the Joomla Events Booking extension (versions 5.0.0 through 5.8.1) that allows unauthorized users to download invoice data. The vulnerability stems from improper ACL (Access Control List) verification during invoice retrieval operations, enabling attackers to access sensitive financial documents they should not have permission to view. This affects any Joomla installation using the vulnerable extension, particularly those processing event registrations and payments. The exposure of invoice data can lead to PII disclosure, financial record theft, and potential compliance violations under regulations like GDPR and PCI-DSS.
While this CVE doesn't map to specific MITRE ATT&CK techniques, Casky's platform would detect the attack patterns underlying this vulnerability through reconnaissance and data exfiltration monitoring. Security practitioners would identify suspicious API calls attempting to access invoice endpoints without proper authorization context, unusual patterns of invoice downloads from non-admin accounts, and HTTP requests manipulating user IDs or invoice identifiers to bypass ownership checks. Though Casky currently shows zero matching skills for this particular CVE, the platform's Claude-powered analysis engine would flag improper permission enforcement, parameter tampering for privilege escalation, and unauthorized resource access as indicators worthy of investigation, helping teams patch vulnerable extensions before active exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-63047. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation