External risk intelligence

Joomla Extension Exposes CDN Credentials in URLs

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-64874

The vulnerability affects a web application extension (Joomla) that manages administrative functions. Such extensions are commonly installed on web servers and content management systems that are typically exposed to the internet to facilitate public website access and remote administrative management.

Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a Joomla extension, specifically related to credential exposure through administrator request URLs. This issue could potentially allow unauthorized access to sensitive information if not properly addressed. The main concern at this time is confirming whether this specific extension is in use and if it is exposed to potential threats.

  • Sensitive credentials may be exposed in web requests.
  • Affects web content management systems.
  • Confirm relevance and exposure of the affected extension.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by accessing the URLs of administrator requests. This exposure in the request URLs leads to CDN credentials being leaked, which could allow an attacker to gain unauthorized access to sensitive information or systems.

  • Network access required.
  • Administrator request URLs trigger.
  • CDN credential leakage risk.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, CDN credentials could be exposed in administrator request URLs. This may affect systems using the affected Joomla extension by potentially leading to unauthorized access or compromise of CDN services.

  • CDN credentials.
  • Exposed in administrator URLs.
  • Potential unauthorized CDN access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability, affecting a Joomla extension, likely resides within the purview of web application or content management system administrators, potentially impacting platform or infrastructure teams. The initial priority is to identify all instances of the affected extension, ascertain its exposure and criticality, and then confirm the responsible owner for coordinated remediation planning.

  • Confirm accountable application or platform owners.
  • Verify extension reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Cache Cleaner Pro extension for Joomla?

Cache Cleaner Pro is a tool developed by Regular Labs for the Joomla content management system. It is designed to help site administrators manage and clear system caches efficiently, improving site performance and maintenance workflows. It integrates with various external services, including Content Delivery Networks (CDNs), to ensure content remains up-to-date across a user's web infrastructure.

How does CVE-2026-64874 cause a security issue?

This vulnerability falls under CWE-200, which is the exposure of sensitive information to an unauthorized actor. In the context of this CVE, the extension inadvertently includes private CDN credentials within the URLs generated for administrator requests. Because these URLs may be logged or stored in various places, this flaw makes sensitive authentication details visible to anyone with access to those request logs.

Do I need to perform a specific action to trigger this flaw?

The vulnerability is triggered when the extension processes administrator requests that contain the embedded credentials. It is important to note that simply visiting the public-facing side of a website does not inherently trigger the leak. The exposure occurs specifically through the handling of administrative request paths where the credential data is incorrectly placed in the URL.

Why is this Joomla vulnerability relevant to my network?

According to Halo Surface Signal, this issue is significant because Joomla extensions used for administrative tasks are frequently deployed on servers that are reachable via the internet. Because the extension manages infrastructure credentials, an attacker who gains access to these leaked URLs could potentially take over control of your CDN services, bypassing the security of the web application itself.

Is there a first step I should take to address this?

Start by identifying every instance of Cache Cleaner Pro currently running within your Joomla environments. Once you have a complete inventory, verify which of these installations are reachable over the internet versus those on internal networks. After mapping these assets, coordinate with the platform owners to prioritize updates or configuration changes recommended by the vendor to secure these credentials.

References