SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64791

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Regular Labs Extension Manager for Joomla is vulnerable due to inconsistent CSRF token and privilege checks, allowing unauthorized backend users or attackers to install, update, or uninstall extensions without proper permissions. This could lead to unauthorized modifications of the Joomla environment, potentially compromising the integrity and security of the application. Joomla administrators and organizations using this extension should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-64791
Severity
HIGH
CVSS
8.8
EPSS
0.13%

Original NVD Description

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.