SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64871

MEDIUM · CVSS 5.4 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Cache Cleaner extension for Joomla exhibits inconsistent checks for CSRF tokens and privilege validation, allowing unauthorized users to purge administrator URLs without proper authentication. This vulnerability could lead to unauthorized cache manipulation, potentially compromising the integrity of the site. Joomla administrators and users of the Cache Cleaner extension should prioritize addressing this issue to safeguard against potential exploitation.

CVE
CVE-2026-64871
Severity
MEDIUM
CVSS
5.4
EPSS
0.09%

Original NVD Description

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.