Junglewise Threat Intelligence

CVE-2026-64791: Regular Labs Extension Manager for Joomla Improper Access Control and CSRF

CVE-2026-64791 · Severity: info · Published 2026-07-22

Vendors: Regular Labs.

Executive brief

A security flaw in the Regular Labs Extension Manager for Joomla allows unauthorized users to manage site extensions. This tool is used to install and update various website features; if exploited, an attacker could install malicious software or remove critical site components. This could lead to a complete site takeover or significant disruption of website operations.

Technical details

The vulnerability stems from improper access control (CWE-284) and a lack of Cross-Site Request Forgery (CSRF) protection (CWE-352) within the administrator routes and install/update/uninstall processing logic. Specifically, the component does not consistently verify that the requesting user has the necessary component-management or installation permissions. An attacker with backend access but limited privileges, or a remote attacker leveraging a CSRF vector against a logged-in administrator, can execute arbitrary extension management tasks. This includes the ability to install, update, or remove Joomla extensions. The issue affects versions 1.0.0 through 9.2.5.

Affected products

  • Regular Labs Regular Labs Extension Manager extension for Joomla 1.0.0-9.2.5

Timeline

  • 2026-07-22: disclosed: CVE published by the Joomla! Project

References