Executive brief
The Articles Anywhere and Modules Anywhere extensions for Joomla contain a security flaw that allows content authors to bypass access restrictions. By using specific tags or property overrides, an author can inadvertently or intentionally display restricted or unpublished content to general website visitors. This could lead to the exposure of sensitive internal information or draft content that was not intended for public viewing.
Technical details
An improper access control vulnerability (CWE-284) exists in the Regular Labs Articles Anywhere and Modules Anywhere extensions for Joomla. The issue stems from the way content tags handle 'ignore' flags or property overrides, which can be manipulated to render articles or modules that are otherwise restricted by ACLs or set to an unpublished state. An attacker with content creation privileges can exploit this to expose sensitive content to unauthorized visitors. The vulnerability affects Articles Anywhere versions 1.0.0 through 18.0.2 and Modules Anywhere versions 1.0.0 through 8.4.1.
Affected products
- Regular Labs Articles Anywhere extension for Joomla 1.0.0-18.0.2
- Regular Labs Modules Anywhere extension for Joomla 1.0.0-8.4.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory