Database Data Disclosure in Joomla Extensions by Regular Labs
CVE-2026-85188
Key Information:
What is CVE-2026-85188?
This vulnerability affects several Joomla extensions developed by Regular Labs, including Advanced Module Manager and Conditional Content. It arises from an authorization flaw that allows an attacker to manipulate the Conditions editor's default Condition Set names, potentially leading to unauthorized database data disclosure. Specifically, the vulnerable code improperly processes SQL identifiers, enabling attackers to interact with arbitrary database fields unrelated to supported integrations, which raises significant security concerns for affected applications.
Affected Version(s)
Advanced Module Manager (Free, Pro) extension for Joomla 9.0.0-12.0.4
Conditional Content (Free, Pro) extension for Joomla 4.0.0-7.1.0
Content Templater (Pro) extension for Joomla 11.0.0-14.1.0
