Junglewise Threat Intelligence

CVE-2026-65757: Regular Labs Modules Anywhere improper access control in editor popup

CVE-2026-65757 · Severity: info · Published 2026-07-23

Technologies: Joomla\!, Regular Labs Modules Anywhere. Vendors: Joomla, Regular Labs.

Executive brief

Regular Labs Modules Anywhere, a Joomla extension used to embed modules within content, contains a security flaw in its editor popup. An authenticated user could potentially view restricted module data they are not authorized to see. This occurs because the system fails to properly verify user permissions or request tokens when displaying information in the editor interface.

Technical details

An improper access control and cross-site request forgery (CSRF) vulnerability exists in the Regular Labs Modules Anywhere extension for Joomla (versions 1.0.0 through 8.4.1). The editor popup component fails to adequately validate session tokens or specific module-level permissions before displaying data. An authenticated attacker could exploit this to access restricted module information that should be inaccessible to their user role. The vulnerability is tracked as CWE-284 and CWE-352.

Affected products

  • Regular Labs Modules Anywhere extension for Joomla 1.0.0 through 8.4.1

Timeline

  • 2026-07-23: advisory: NVD published the CVE record based on Joomla! Project data.

References

Related threats