CVE-2026-64798
This vulnerability affects a Joomla extension from regularlabs.com. It allows attackers to use insecure login URL keys that are generated with weak randomness, enabling unauthorized access. The flaw is critical because it can grant full control over the site.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Joomla sites that use the regularlabs.com IP login extension, which generates persistent URL login keys with insufficient entropy.
Real-world impact
An attacker could log in without a password, gaining full administrative control over the Joomla site and all its data.
Why this severity
The CVSS score of 9.1 reflects that the flaw is network‑exploitable with no authentication or user interaction, and it can lead to complete compromise of confidentiality and integrity.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 22, 2026 · 10d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.