Description
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
Published: 2026-07-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cache Cleaner Pro extension for Joomla stores CDN credentials in the query string of administrator request URLs. This results in a direct information disclosure that allows an unauthorized party to obtain credentials that provide control over the CDN service. Because the flaw is marked as CWE-200 (Information Exposure), the exposed data is highly valuable and can be used to compromise content delivery, potentially to modify cached content or serve as a foothold for further attacks. The CVE description does not indicate limited scope, implying that any installation of the extension that has not received a patch may be vulnerable.

Affected Systems

The Cache Cleaner Pro extension developed by regularlabs.com for Joomla is the affected component. The public CVE entry does not list specific version numbers; therefore, any user of the extension that has not applied the latest update is potentially at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation at the moment and it is not catalogued in CISA KEV. Based on the description, it is inferred that the likely attack vector is an attacker who can read request logs or intercept traffic, for example via compromised network devices or temporary access to the site's logging infrastructure. The vulnerability does not require higher‑level Joomla privileges; read access to logs or traffic is sufficient. The high CVSS reflects that successful exploitation would grant the attacker full control of the CDN service, potentially leading to significant availability or confidentiality impacts.

Generated by OpenCVE AI on August 3, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Cache Cleaner Pro extension to the latest release that removes CDN credentials from request URLs.
  • Configure Joomla and the web server to enforce HTTPS for all admin traffic and prevent logging of query parameters that may contain sensitive credentials.
  • Implement web‑application‑firewall or log‑filtering rules to strip or mask any sensitive parameters before they are persisted in logs or displayed publicly.

Generated by OpenCVE AI on August 3, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com cache Cleaner Pro Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com cache Cleaner Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description CDN credentials were exposed in administrator request URLs. Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

Thu, 23 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description CDN credentials were exposed in administrator request URLs.
Title Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension
Weaknesses CWE-200
References

Subscriptions

Regularlabs.com Cache Cleaner Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T13:29:53.752Z

Reserved: 2026-07-20T18:35:16.486Z

Link: CVE-2026-64874

cve-icon Vulnrichment

Updated: 2026-07-27T13:28:06.814Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:52.297

Modified: 2026-07-27T14:16:59.813

Link: CVE-2026-64874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor