Junglewise Threat Intelligence

CVE-2026-65712: Regular Labs CDN for Joomla Pro path traversal in CDN versioning

CVE-2026-65712 · Severity: info · Published 2026-07-23

Vendors: Regular Labs.

Executive brief

A vulnerability in the CDN for Joomla Pro extension allows unauthorized access to information about files on the server. This extension is used to integrate Content Delivery Networks with Joomla websites to improve performance. An attacker could exploit this to determine if specific files exist outside of the intended website directory and view their modification dates, which could be used to plan further attacks or gather sensitive system metadata.

Technical details

A path traversal vulnerability (CWE-22) exists in the CDN versioning component of the Regular Labs CDN for Joomla Pro extension. The software fails to properly restrict file path checks to the intended site directory. A remote attacker can provide manipulated paths to verify the existence of files elsewhere on the local file system and retrieve their modification metadata. This issue affects versions 1.0.0 through 7.3.7. While it does not allow for full file content disclosure, it facilitates reconnaissance by exposing system structure and file timestamps.

Affected products

  • Regular Labs CDN for Joomla Pro extension for Joomla 1.0.0 through 7.3.7

Timeline

  • 2026-07-23: disclosed: CVE published by Joomla! Project
  • 2026-07-23: advisory

References