CVE-2026-64791

CVE-2026-64791: Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager

Vendor Regularlabs.com
Product Regular Labs Extension Manager extension for Joomla
Weakness CWE-352 · CSRF
Published July 22, 2026
Last update July 23, 2026

CVSS base score

What the vulnerability does

01Description

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.

Key dates

02Disclosure timeline

July 22, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

04Related CVE