CVE-2026-64797

Summary

IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

Affected Software

VendorProductVersion RangeStatus
regularlabs.comIP Login extension for Joomla1.0.0-6.2.5affected

Weaknesses

  • CWE-290: CWE-290 Authentication Bypass by Spoofing

References