CVE-2026-64873

9.8

Regular Labs · Cache Cleaner Pro extension for Joomla

A Server-Side Request Forgery vulnerability in the Regular Labs Cache Cleaner Pro extension for Joomla allows unauthenticated attackers to access internal or reserved network services.

Executive summary

The Regular Labs Cache Cleaner Pro extension for Joomla is vulnerable to unauthenticated Server-Side Request Forgery, potentially allowing full compromise of internal network resources.

Vulnerability

This vulnerability is a Server-Side Request Forgery (CWE-918) flaw. It occurs when the extension improperly handles custom query URLs, allowing an unauthenticated attacker to force the server to send requests to arbitrary internal destinations.

Business impact

The ability to perform SSRF from a web server allows an attacker to bypass perimeter defenses and interact with internal network assets that are not exposed to the internet. This could lead to the exposure of sensitive configuration data, internal service interaction, or further lateral movement within the network. Given the CVSS score of 9.8, this vulnerability represents a critical risk to the confidentiality, integrity, and availability of the entire internal infrastructure.

Remediation

Immediate Action: Since a specific patch version is currently unknown, administrators should immediately restrict access to the affected Joomla instance or disable the Cache Cleaner Pro extension until an update is released by the vendor.

Proactive Monitoring: Review web server and firewall logs for unusual outbound requests originating from the Joomla server, particularly those targeting internal IP addresses or reserved network ranges.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious outbound traffic or requests containing internal-facing URL patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a severe risk due to its potential to expose internal network segments to unauthenticated remote attackers. Organizations using the Cache Cleaner Pro extension must prioritize monitoring for vendor updates and implement temporary access restrictions to minimize the attack surface until a validated security patch is available.

More Regular Labs CVEs

Sources