Junglewise Threat Intelligence

CVE-2026-64875: Regular Labs GeoIP extension for Joomla GeoIP-rule bypass via IP spoofing

CVE-2026-64875 · Severity: info · CVSS 0 · Published 2026-07-23

Technologies: Regular Labs GeoIP. Vendors: Regular Labs.

Executive brief

A vulnerability in the Regular Labs GeoIP extension for Joomla allows users to bypass location-based restrictions. This extension is used to identify the geographic location of website visitors to show or hide specific content. By spoofing their network headers, an attacker can trick the system into thinking they are in a different location, potentially gaining access to restricted regional content or bypassing security rules.

Technical details

The Regular Labs GeoIP extension for Joomla (versions 1.0.0 through 6.3.8) is vulnerable to authentication bypass via spoofing (CWE-290). The library trusts HTTP forwarded client-IP headers (such as X-Forwarded-For) without proper validation or verification of the source. A remote, unauthenticated attacker can provide a spoofed IP address in these headers to manipulate the GeoIP lookup result. This allows the attacker to bypass geographic access controls or conditional content rules that rely on the visitor's location.

Affected products

  • Regular Labs GeoIP extension for Joomla 1.0.0 through 6.3.8

Timeline

  • 2026-07-23: disclosed: CVE published by Joomla! Project

References

Related threats