{"api_version":"1","generated_at":"2026-07-24T18:46:21+00:00","cve":"CVE-2026-64796","urls":{"html":"https://cve.report/CVE-2026-64796","api":"https://cve.report/api/cve/CVE-2026-64796.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64796","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64796"},"summary":{"title":"Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension","description":"Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.","state":"PUBLISHED","assigner":"Joomla","published_at":"2026-07-22 21:18:10","updated_at":"2026-07-23 16:17:48"},"problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":[],"references":[{"url":"https://regularlabs.com/","name":"https://regularlabs.com/","refsource":"security@joomla.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64796","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64796","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"regularlabs.com","product":"Sourcerer extension for Joomla","version":"affected 1.0.0-12.2.8","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64796","cve":"CVE-2026-64796","epss":"0.001910000","percentile":"0.090370000","score_date":"2026-07-23","updated_at":"2026-07-24 00:10:10"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Sourcerer extension for Joomla","vendor":"regularlabs.com","versions":[{"status":"affected","version":"1.0.0-12.2.8"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection."}],"value":"Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection."}],"impacts":[{"capecId":"CAPEC-242","descriptions":[{"lang":"en","value":"CAPEC-242: Code Injection"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-23T14:58:14.944Z","orgId":"6ff30186-7fb7-4ad9-be33-533e7b05e586","shortName":"Joomla"},"references":[{"tags":["product"],"url":"https://regularlabs.com/"}],"source":{"discovery":"UNKNOWN"},"title":"Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension","x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"6ff30186-7fb7-4ad9-be33-533e7b05e586","assignerShortName":"Joomla","cveId":"CVE-2026-64796","datePublished":"2026-07-22T20:42:49.934Z","dateReserved":"2026-07-20T18:16:31.593Z","dateUpdated":"2026-07-23T14:58:14.944Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-22 21:18:10","lastModifiedDate":"2026-07-23 16:17:48","problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64796","Ordinal":"1","Title":"Joomla Extension - regularlabs.com - various code injection vect","CVE":"CVE-2026-64796","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64796","Ordinal":"1","NoteData":"Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.","Type":"Description","Title":"Joomla Extension - regularlabs.com - various code injection vect"}]}}}