Token Enforcement and Permissions Vulnerability in Regular Labs Products
CVE-2026-63280

8.8HIGH

What is CVE-2026-63280?

A vulnerability exists in Regular Labs products where the administration does not consistently enforce security tokens and permissions for components and mapped items. This could lead to unauthorized access and manipulation of sensitive system settings, thereby exposing systems to potential attacks. It highlights the importance of robust token validation and strict permissions management to safeguard against unauthorized actions.

Affected Version(s)

Advanced Module Manager extension for Joomla 1.0.0-11.0.1

Conditional Content extension for Joomla 1.0.0-6.0.0

Content Templater Pro extension for Joomla 1.0.0-13.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.