What is CVE-2026-64871?
CVE-2026-64871: This is a vulnerability in the Joomla Cache Cleaner extension by regularlabs.com. Administrator URL purges do not consistently require a valid CSRF token and cache-management permission. Attackers could potentially trick an authenticated administrator into performing unauthorized cache clearing operations.
Azərbaycanca: CVE-2026-64871: regularlabs.com tərəfindən hazırlanan Joomla Cache Cleaner genişlənməsində zəiflik aşkarlanıb. Administrator URL təmizləmə əməliyyatları ardıcıl olaraq etibarlı CSRF tokeni və keş idarəetmə icazəsi tələb etmir. Zərərçəkənlər xüsusi hazırlanmış sorğu vasitəsilə istifadəçini aldatmaqla icazəsiz keş təmizləmə əməliyyatları icra edə bilərlər.
Related CVEs
link basis: same weakness class CWE-352; shared vendor: regularlabs.com
FAQ2
What security mechanism is missing in the Joomla Cache Cleaner extension that causes CVE-2026-64871?
The vulnerability stems from administrator URL purge operations not consistently requiring a valid CSRF token and cache-management permission.
What can an attacker achieve by exploiting CVE-2026-64871?
An attacker could trick an authenticated administrator into performing unauthorized cache clearing operations via a specially crafted request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.