External risk intelligence

Joomla Conditional Content Extension Authenticated Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-85192

The vulnerability affects a Joomla extension. While the site is internet-facing, exploitation requires authenticated access with elevated privileges to modify article content and inject PHP code. It is not an unauthenticated endpoint, making exploitation dependent on compromised credentials or an existing privileged user.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in a Joomla extension from regularlabs.com that allows authenticated users with elevated privileges to execute remote code. The issue stems from the extension's Conditional Content feature accepting inline PHP code within articles, which is then evaluated without proper authorization checks, enabling the execution of commands as the web server process. The main concern is confirming relevance and exposure.

  • Unauthenticated users can run code on your site.
  • Critical code execution vulnerability affecting Joomla.
  • Confirm relevance and exposure of this Joomla extension.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated, privileged access to a Joomla site can inject and execute arbitrary PHP code by creating or editing articles with specially crafted content. The vulnerable Conditional Content extension processes this PHP code when the article is published, allowing the attacker to run commands with the privileges of the web server.

  • Requires authenticated privileged access.
  • Triggered by publishing articles with PHP.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, authenticated and privileged users could execute arbitrary PHP code within the web server process by embedding it in article content. This could lead to the compromise of the web server and any data it can access.

  • Web server process and data.
  • PHP code execution via article content.
  • System compromise and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security teams and platform owners are responsible for addressing this critical vulnerability in the Conditional Content extension. The first step is to identify all instances of the affected extension, determine their exposure, and confirm the business criticality of each deployment to prioritize remediation efforts.

  • Own: Platform and security teams.
  • Verify: Identify all affected installations.
  • Act: Plan and coordinate vendor or internal fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Conditional Content extension for Joomla?

Conditional Content is a third-party plugin from Regular Labs designed to enhance article management. It allows users to control the visibility of content sections based on specific criteria. By embedding custom syntax directly into articles, it helps site administrators display or hide information dynamically without needing to create separate pages or complex templates.

What does CWE-94 mean for CVE-2026-85192?

CWE-94 refers to Improper Control of Generation of Code. In this specific vulnerability, the extension fails to validate that the person creating or editing an article has permission to write and run server-side scripts. Because the software treats provided text as executable instructions rather than just content, it allows the system to process unauthorized PHP commands.

How is this Joomla vulnerability triggered?

The issue is triggered when an article containing inline PHP rules is published. It does not occur if the malicious syntax remains in a draft state or if no PHP-based rules are embedded in the content. The code executes only when the extension's evaluator processes the article as part of the page rendering lifecycle.

Is my site at risk if it is internet-facing?

According to Halo Surface Signal, while the Joomla site itself is internet-facing, this specific bug is not reachable by anonymous visitors. It requires an attacker to already have valid, privileged credentials to edit articles. The primary risk is therefore tied to compromised administrator accounts rather than general web traffic.

How do I respond to this vulnerability?

Begin by auditing your Joomla environment to confirm if the Conditional Content extension is installed and which version is active. If you are running a version prior to 8.0.0, prioritize the update process. Coordinate with your web team to ensure all instances are identified and patched to eliminate the risk of unauthorized code execution.

References