CVE-2026-85192
largeAuthenticated RCE via inline PHP in Regular Labs Conditional Content for Joomla
Conditional Content and Conditional Content Pro, Joomla extensions from Regular Labs, in versions before 8.0.0 accept inline PHP inside Condition Rules article syntax and pass it to their conditions evaluator without checking who authored the article. Because Joomla's normal Author text filter preserves the syntax, any authenticated user with article-authoring rights can embed PHP that runs as the web-server process as soon as the article is published and rendered. This effectively lets an author-level account escalate to full server-side code execution, reflected in a CVSS 4.0 score of 9.4 (critical) with a network attack vector and high privileges required. Sites running Conditional Content or Conditional Content Pro below 8.0.0 are affected. No public proof of concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.
What to do: Upgrade Conditional Content and Conditional Content Pro to version 8.0.0 or later immediately. Until patched, restrict article-authoring rights to trusted users only, and review existing articles' Conditional Content rules for unexpected inline PHP. Audit author accounts and recently published articles for signs of injected code, since any author could have achieved code execution as the web-server user.
| Regular Labs (regularlabs.com) Conditional Content (Joomla extension) | < 8.0.0 |
| Regular Labs (regularlabs.com) Conditional Content Pro (Joomla extension) | < 8.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions, the PHP is passed to the Conditions evaluator without checking who authored the article. Joomla's normal Author text filter preserves the syntax, so publishing the article causes the code to run as the web-server process.
- Ecosystems
- Joomla
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.