What is CVE-2026-64876?
CVE-2026-64876 is a security flaw in Joomla's Regular Labs GeoIP extension. It stems from inconsistent CSRF token and privilege checks on database update requests, potentially allowing unauthorized updates. Users should apply the patch provided by Regular Labs to mitigate the risk.
Azərbaycanca: CVE-2026-64876 Joomla-nın Regular Labs GeoIP genişlənməsində aşkar edilmiş təhlükəsizlik boşluğudur. Bu zəiflik verilənlər bazası yeniləmə sorğularında CSRF token yoxlamalarının və super istifadəçi imtiyaz nəzarətlərinin qeyri-ardıcıl tətbiqindən qaynaqlanır ki, bu da potensial icazəsiz yeniləmələrə səbəb ola bilər. İstifadəçilər Regular Labs tərəfindən təqdim edilən yenilənmiş versiyanı tətbiq etməklə riski aradan qaldırmalıdırlar.
Related CVEs
link basis: same weakness class CWE-352; shared vendor: regularlabs.com
FAQ2
Which Joomla extension is affected by CVE-2026-64876?
This vulnerability affects the Regular Labs GeoIP extension for Joomla.
How can users mitigate the risk of CVE-2026-64876?
They should apply the updated version provided by Regular Labs to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.