Description
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
Published: 2026-07-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

User tags, filters and conditions in Regular Labs' Articles Anywhere and Users Anywhere Joomla extensions can be abused to retrieve user fields that are not properly restricted. The vulnerability allows an attacker to craft content that exposes authentication‑related data, raw user parameters, or restricted contact details, leading to leakage of confidential information. This weakness is a classic example of improper authorization enforcement, classified as CWE‑284.

Affected Systems

All Joomla installations that use the Articles Anywhere or Users Anywhere extensions from Regular Labs are potentially impacted. Because specific affected versions are not listed, any instance of these extensions without an updated access‑control fix should be considered vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, indicating very low exploit probability, and the vulnerability is not listed in CISA KEV. The CVSS score of 6.5 indicates moderate severity. However, the potential impact of disclosing authentication and contact information is high, which raises the overall risk assessment. The likely attack vector involves any user who can input custom tags or filter expressions through the front‑end or an extension configuration page, and the exploit can be performed without elevated privileges on the site.

Generated by OpenCVE AI on August 3, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Articles Anywhere and Users Anywhere extensions to the latest released version that includes the access‑control fix.
  • If an immediate upgrade is not possible, disable or restrict the interface that allows users to insert custom tags, filters, or conditions.
  • Review the extension configuration and data or raw parameters.

Generated by OpenCVE AI on August 3, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com users Anywhere Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com users Anywhere Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details. Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
Title Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions
Weaknesses CWE-284
References

Subscriptions

Regularlabs.com Articles Anywhere Extension For Joomla Users Anywhere Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T13:34:11.997Z

Reserved: 2026-07-20T18:16:31.592Z

Link: CVE-2026-64794

cve-icon Vulnrichment

Updated: 2026-07-27T13:31:28.584Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:10.553

Modified: 2026-07-27T15:17:08.047

Link: CVE-2026-64794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:15:04Z

Weaknesses