Junglewise Threat Intelligence

CVE-2026-64876: Regular Labs GeoIP extension for Joomla improper access control in database updates

CVE-2026-64876 · Severity: info · CVSS 0 · Published 2026-07-23

Technologies: Regular Labs GeoIP. Vendors: Regular Labs.

Executive brief

The GeoIP extension for Joomla, a tool used to identify the geographic location of website visitors, contains a security flaw in how it handles database updates. An attacker could potentially trigger unauthorized changes to the database because the software fails to properly verify administrative permissions and security tokens. This could lead to unauthorized data modification or system instability.

Technical details

The GeoIP extension for Joomla (versions 1.0.0 through 6.3.8) fails to consistently perform Super User permission checks and anti-CSRF token validation during database-update requests. This vulnerability is classified under CWE-284 (Improper Access Control) and CWE-352 (Cross-Site Request Forgery). A remote attacker could potentially exploit this by tricking an authenticated administrator into visiting a malicious site or by sending crafted requests that bypass authorization logic. Successful exploitation allows for unauthorized updates to the extension's database components.

Affected products

  • Regular Labs GeoIP extension for Joomla 1.0.0 through 6.3.8

Timeline

  • 2026-07-23: disclosed: CVE published by Joomla! Project

References

Related threats