SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64797

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Joomla Extension from regularlabs.com is vulnerable due to an IP spoofing flaw in its IP Login feature, which trusts forwarded client-IP headers without necessitating a configured trusted proxy. This vulnerability allows attackers to spoof their IP addresses, potentially impersonating legitimate users and gaining unauthorized access to mapped accounts. Organizations using this extension should prioritize remediation to protect against unauthorized access and account compromise.

CVE
CVE-2026-64797
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.