SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64798

CRITICAL · CVSS 9.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Joomla Extension from regularlabs.com is vulnerable due to the use of a non-cryptographic random generator for creating persistent URL login keys, leading to insufficient entropy. This flaw allows attackers to potentially exploit predictable login URLs, compromising user accounts and sensitive data. Organizations using this extension should prioritize remediation to mitigate the risk of unauthorized access and data breaches.

CVE
CVE-2026-64798
Severity
CRITICAL
CVSS
9.1
EPSS
0.24%

Original NVD Description

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.