CVE-2026-74253
10.0Regular Labs · Sourcerer extension for Joomla
The Regular Labs Sourcerer extension for Joomla is vulnerable to unauthenticated remote code execution due to improper handling of reflected user input within rendered HTML blocks.
Executive summary
A critical vulnerability in the Regular Labs Sourcerer extension for Joomla allows unauthenticated attackers to achieve remote code execution on affected systems.
Vulnerability
This is an improper control of code generation (CWE-94) flaw. The extension fails to validate input within {source} blocks in rendered HTML, allowing an unauthenticated attacker to inject and execute arbitrary code.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code represents the highest level of security risk. Successful exploitation could lead to a complete system compromise, including unauthorized access to site data, administrative account takeover, and potential lateral movement within the hosting environment. Given the CVSS score of 10.0, this issue poses an immediate and catastrophic threat to business continuity and data integrity.
Remediation
Immediate Action: Update the Regular Labs Sourcerer extension for Joomla to version 14.0.0 or later immediately.
Proactive Monitoring: Review web server and application logs for suspicious {source} block patterns or unexpected outbound network connections originating from the Joomla instance.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to filter or block malicious payloads targeting the Sourcerer extension parameters.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is critical and requires immediate patching. Organizations should prioritize updating the Sourcerer extension across all Joomla environments to prevent potential exploitation. If patching is not immediately feasible, consider disabling the extension until an update can be applied.