Remote Code Execution Vulnerability in Joomla Extension by Regular Labs
CVE-2026-85192

9.4CRITICAL

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-85192?

The Conditional Content Pro extension for Joomla prior to version 8.0.0 contains a vulnerability that allows authenticated, privileged users to execute arbitrary PHP code. This occurs because the extension processes inline PHP Condition Rules without adequate permission checks. As a result, any PHP code embedded within the article syntax is evaluated directly on the server, which can lead to significant security breaches and unauthorized control over the web environment.

Affected Version(s)

Conditional Content Pro extension for Joomla 1.0.0-7.1.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.