CSRF Vulnerability in Regular Labs AJAX Endpoints Affecting Privileged Access
CVE-2026-63265

8HIGH

What is CVE-2026-63265?

A security weakness in Regular Labs AJAX endpoints was identified where valid CSRF tokens were not consistently enforced. This vulnerability allows authenticated users with lower privileges to perform actions or access data beyond their authorization level. It poses a significant risk as malicious actors can exploit this weakness to engage in unauthorized lookups or modifications, leading to potential data breaches and compromised system integrity.

Affected Version(s)

Advanced Module Manager extension for Joomla 1.0.0-11.0.1

Articles Anywhere extension for Joomla 1.0.0-18.0.2

Articles Field extension for Joomla 1.0.0-4.7.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.