CVE-2026-65757
Regular Labs · Modules Anywhere extension for Joomla
The Modules Anywhere extension for Joomla contains vulnerabilities related to Cross-Site Request Forgery and improper access control.
Executive summary
Vulnerabilities in the Modules Anywhere extension for Joomla could allow an authenticated attacker to perform unauthorized actions or gain unauthorized access.
Vulnerability
The extension is affected by Cross-Site Request Forgery (CWE-352) and Improper Access Control (CWE-284). These flaws require the attacker to be authenticated with low privileges to trigger the malicious requests, potentially allowing them to modify module configurations or perform unauthorized tasks.
Business impact
With a CVSS score of 8.1, this vulnerability represents a significant risk to the integrity and availability of the Joomla environment. Unauthorized access to module configurations could allow an attacker to deface the website, inject malicious content, or redirect traffic, causing reputational damage and potential service disruption.
Remediation
Immediate Action: Check the Regular Labs website for the latest version of the Modules Anywhere extension and apply the update immediately.
Proactive Monitoring: Audit Joomla user logs for unauthorized module changes or unexpected administrative actions performed by low-privileged accounts.
Compensating Controls: Implement strict access control lists within the Joomla backend to restrict the ability of low-privileged users to manage extensions or site configuration.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Administrators should update the Modules Anywhere extension as a priority to address the access control and CSRF issues. If an immediate update is not feasible, consider temporarily disabling the extension to prevent exploitation while a maintenance window is scheduled.