What is CVE-2026-74253?
An unauthenticated Remote Code Execution (RCE) vulnerability has been discovered in the Regular Labs Sourcerer extension for Joomla before version 14.0.0. The flaw arises because the extension processes {source} blocks found in the final rendered HTML without reliably verifying the origin of that code. Users should immediately update the Sourcerer extension to version 14.0.0 or later.
Azərbaycanca: Joomla üçün Regular Labs Sourcerer genişlənməsinin 14.0.0-dən əvvəlki versiyalarında autentifikasiya tələb etməyən uzaqdan kod icrası (Unauthenticated RCE) zəifliyi aşkarlanıb. Problem genişlənmənin son render edilmiş HTML-də tapdığı {source} bloklarının mənbəyini düzgün yoxlamadan emal etməsindən qaynaqlanır. İstifadəçilər dərhal Sourcerer genişlənməsini ən azı 14.0.0 versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which Joomla extension is affected by the CVE-2026-74253 vulnerability?
The Regular Labs Sourcerer extension.
What is the root cause of this RCE vulnerability?
The extension processes {source} blocks found in the final rendered HTML without reliably verifying the origin of that code.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.