Description
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to cause restricted or administrator‑only content to be indexed by Joomla’s Smart Search feature using the identity of the indexing administrator. Consequently, content that should be hidden from public visitors is stored in the public search index and becomes viewable by any site visitor. This leads to accidental disclosure of confidential or privileged information without the need for authentication. The flaw is a CWE‑524 information disclosure vulnerability.

Affected Systems

Affected vendors include Regular Labs, which provides several Joomla extensions such as Articles Anywhere, Conditional Content, Modules Anywhere, ReReplacer, Snippets Pro, Sourcerer, and Tabs & Accordions Pro. The specific versions impacted are not listed in the advisory, so any release that patch is applied.

Risk and Exploitability

The EPSS score of 0.00249 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a normal search request made by a publicly accessible visitor, which triggers the indexing process. An attacker does not need privileged credentials to leverage the flaw; they merely need to cause the search index to be updated. The impact is purely informational, exposing content that was intended to remain restricted. Organizations using these Regular Labs extensions should consider the vulnerability a low‑to‑moderate risk until a fix is applied, but should not any breach of content confidentiality can have downstream effects on trust and compliance.

Generated by OpenCVE AI on August 3, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade the affected Regular Labs extensions to the most indexing flaw.
  • In the Joomla Smart Search configuration, disable indexing for content that is marked as restricted or administrator‑only to prevent the public index.
  • Clear the existing search index to remove any previously indexed restricted items, then rebuild the index after making the above configuration changes.

Generated by OpenCVE AI on August 3, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com conditional Content Extension For Joomla
Regularlabs.com modules Anywhere Extension For Joomla
Regularlabs.com rereplacer Extension For Joomla
Regularlabs.com snippets Pro Extension For Joomla
Regularlabs.com sourcerer Extension For Joomla
Regularlabs.com tabs & Accordions Pro Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com conditional Content Extension For Joomla
Regularlabs.com modules Anywhere Extension For Joomla
Regularlabs.com rereplacer Extension For Joomla
Regularlabs.com snippets Pro Extension For Joomla
Regularlabs.com sourcerer Extension For Joomla
Regularlabs.com tabs & Accordions Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors. Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.
Title Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions
Weaknesses CWE-524
References

Subscriptions

Regularlabs.com Articles Anywhere Extension For Joomla Conditional Content Extension For Joomla Modules Anywhere Extension For Joomla Rereplacer Extension For Joomla Snippets Pro Extension For Joomla Sourcerer Extension For Joomla Tabs & Accordions Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-28T05:31:54.131Z

Reserved: 2026-07-20T18:16:31.592Z

Link: CVE-2026-64792

cve-icon Vulnrichment

Updated: 2026-07-27T17:37:36.732Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:10.337

Modified: 2026-07-27T18:16:59.767

Link: CVE-2026-64792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:15:04Z

Weaknesses
  • CWE-524

    Use of Cache Containing Sensitive Information