Description
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.
Published: 2026-07-22
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Articles Anywhere and Modules Anywhere Joomla extensions allows a content author to use ignore flags or property overrides so that restricted or unpublished articles and modules are rendered publicly. This flaw bypasses Joomla’s built‑in access restrictions, enabling confidential or unpublished material to be displayed to visitors who normally lack the required permissions. It is inferred that the attacker would need to be an authenticated content author with the ability to apply these overrides to create the bypass.

Affected Systems

Joomla content management systems that have the Articles Anywhere or Modules Anywhere extensions from regularlabs.com installed. All versions of these extensions that have not received the vendor’s patch are affected, irrespective of the underlying Joomla core version.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated content author to craft ignore flags or property overrides; once created, any visitor who accesses the affected content rendering endpoint can view the previously restricted material. No additional prerequisites are required beyond the authoring role. It is inferred that the attack vector would involve an eligible user leveraging rendering options to expose the content to a broader audience.

Generated by OpenCVE AI on August 2, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest stable release of Articles Anywhere and Modules Anywhere that contains the vendor patch.
  • Review existing content to remove ignore flags or property overrides that grant unintended access, and restrict the ability to use such flags to administrators only.
  • Adjust Joomla permissions so that only trusted user groups can edit content tags that affect rendering.
  • Verify that the extensions enforce proper access checks on content display; if no patch is available consider disabling or uninstalling the extensions.

Generated by OpenCVE AI on August 2, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com modules Anywhere Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com modules Anywhere Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access. Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.
Title Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions
Weaknesses CWE-284
References

Subscriptions

Regularlabs.com Articles Anywhere Extension For Joomla Modules Anywhere Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T13:34:13.847Z

Reserved: 2026-07-20T18:16:31.592Z

Link: CVE-2026-64793

cve-icon Vulnrichment

Updated: 2026-07-27T13:30:22.929Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:10.447

Modified: 2026-07-27T14:16:59.510

Link: CVE-2026-64793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:30:17Z

Weaknesses