Executive brief
Multiple Joomla extensions from Regular Labs contain a flaw where the Smart Search indexing process incorrectly uses an administrator's identity to generate content. This can cause private or restricted information, intended only for administrators, to be saved into the public search index. As a result, unauthorized visitors could discover sensitive content simply by using the website's search feature.
Technical details
A vulnerability exists in several Regular Labs extensions for Joomla (including Articles Anywhere, Sourcerer, and others) related to how they handle Smart Search indexing. The root cause is a failure to properly isolate the security context during the indexing process, causing the system to render content using the administrator's permissions (CWE-524). Consequently, restricted or administrator-only content is stored in the public search index. An attacker or guest user can then retrieve this sensitive information through standard search queries. The issue affects multiple versions across the product suite as of July 2026.
Affected products
- Regular Labs Articles Anywhere extension for Joomla 1.0.0-18.0.2
- Regular Labs Conditional Content extension for Joomla 1.0.0-6.0.0
- Regular Labs Modules Anywhere extension for Joomla 1.0.0-8.4.1
- Regular Labs ReReplacer extension for Joomla 1.0.0-15.0.3
- Regular Labs, Sourcerer extension for Joomla 1.0.0-12.2.8
- Regular Labs Tabs & Accordions Pro extension for Joomla 1.0.0-2.5.6
- Regular Labs Snippets Pro extension for Joomla 1.0.0-9.3.10
Timeline
- 2026-07-22: disclosed: CVE record published by Joomla! Project