ZeroHour

CVE-2026-85192

large

Authenticated RCE via inline PHP in Regular Labs Conditional Content for Joomla

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

Conditional Content and Conditional Content Pro, Joomla extensions from Regular Labs, in versions before 8.0.0 accept inline PHP inside Condition Rules article syntax and pass it to their conditions evaluator without checking who authored the article. Because Joomla's normal Author text filter preserves the syntax, any authenticated user with article-authoring rights can embed PHP that runs as the web-server process as soon as the article is published and rendered. This effectively lets an author-level account escalate to full server-side code execution, reflected in a CVSS 4.0 score of 9.4 (critical) with a network attack vector and high privileges required. Sites running Conditional Content or Conditional Content Pro below 8.0.0 are affected. No public proof of concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

What to do: Upgrade Conditional Content and Conditional Content Pro to version 8.0.0 or later immediately. Until patched, restrict article-authoring rights to trusted users only, and review existing articles' Conditional Content rules for unexpected inline PHP. Audit author accounts and recently published articles for signs of injected code, since any author could have achieved code execution as the web-server user.

Affected
Regular Labs (regularlabs.com) Conditional Content (Joomla extension)< 8.0.0
Regular Labs (regularlabs.com) Conditional Content Pro (Joomla extension)< 8.0.0
Estimated exposure
largetens of thousands of Joomla sites (order of magnitude ~10,000–100,000) — Joomla powers roughly 2% of all websites worldwide and Regular Labs is one of the most widely installed Joomla extension vendors, but no official active-install count for Conditional Content is published, so this is clearly an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions, the PHP is passed to the Conditions evaluator without checking who authored the article. Joomla's normal Author text filter preserves the syntax, so publishing the article causes the code to run as the web-server process.

Ecosystems
Joomla
Weakness
CWE-94
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.