Description
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to insert forged client‑IP headers that the IP Login extension accepts without verifying the source proxy. Because those headers are used to determine automatic login, the attacker can cause the system to credential an account that matches the spoofed IP. This can lead to unauthorized access.

Affected Systems

The affected product is the regularlabs.com IP Login extension for Joomla. No specific versions are listed, so any installation that has not applied an official update may be vulnerable.

Risk and Exploitability

The extension relies on trust of a forwarded client‑IP header without requiring configuration of a trusted proxy, making the attack vector straightforward for anyone able to control HTTP request headers. The CVSS Score is 7.5, the EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. However, the capacity to spoof identity and gain unauthorized account access suggests a high risk for organizations that use this extension without additional safeguards.

Generated by OpenCVE AI on August 2, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the regularlabs.com IP Login extension to the latest version that includes the fix for untrusted forwarded IP headers.
  • Configure the extension to trust only known, properly authenticated proxy servers and reject all other forwarded IP headers.
  • If an update is unavailable, disable the automatic login feature that relies on the client‑IP header or implement your own strict IP validation.
  • Review account mapping and restrict privileges for accounts that can be auto‑logged in based on IP.

Generated by OpenCVE AI on August 2, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com ip Login Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com ip Login Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts. Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
Title Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension
Weaknesses CWE-290
References

Subscriptions

Regularlabs.com Ip Login Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-29T05:39:44.152Z

Reserved: 2026-07-20T18:16:31.593Z

Link: CVE-2026-64797

cve-icon Vulnrichment

Updated: 2026-07-28T14:08:12.561Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:10.870

Modified: 2026-07-28T16:20:04.800

Link: CVE-2026-64797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:30:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing