CVE-2026-65757

Regular Labs · Modules Anywhere extension for Joomla

The Modules Anywhere extension for Joomla contains vulnerabilities related to Cross-Site Request Forgery and improper access control.

Executive summary

Vulnerabilities in the Modules Anywhere extension for Joomla could allow an authenticated attacker to perform unauthorized actions or gain unauthorized access.

Vulnerability

The extension is affected by Cross-Site Request Forgery (CWE-352) and Improper Access Control (CWE-284). These flaws require the attacker to be authenticated with low privileges to trigger the malicious requests, potentially allowing them to modify module configurations or perform unauthorized tasks.

Business impact

With a CVSS score of 8.1, this vulnerability represents a significant risk to the integrity and availability of the Joomla environment. Unauthorized access to module configurations could allow an attacker to deface the website, inject malicious content, or redirect traffic, causing reputational damage and potential service disruption.

Remediation

Immediate Action: Check the Regular Labs website for the latest version of the Modules Anywhere extension and apply the update immediately.

Proactive Monitoring: Audit Joomla user logs for unauthorized module changes or unexpected administrative actions performed by low-privileged accounts.

Compensating Controls: Implement strict access control lists within the Joomla backend to restrict the ability of low-privileged users to manage extensions or site configuration.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Administrators should update the Modules Anywhere extension as a priority to address the access control and CSRF issues. If an immediate update is not feasible, consider temporarily disabling the extension to prevent exploitation while a maintenance window is scheduled.