CVE-2026-64797
Received Received - Intake

IP Spoofing in Joomla Due to Unverified X-Forwarded-For Headers

Vulnerability report for CVE-2026-64797, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Joomla! Project

Description

IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves IP Login in Joomla trusting forwarded client-IP headers without verifying if the proxy is trusted. Attackers can spoof the IP address used for automatic login, potentially gaining unauthorized access to accounts.

Impact Analysis

If you use Joomla with IP Login enabled, attackers could impersonate your users by spoofing their IP addresses. This may lead to unauthorized access, data breaches, or account takeovers.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements under GDPR and HIPAA. Organizations may face compliance penalties if user data is exposed due to this flaw.

Mitigation Strategies

Configure trusted proxy settings to validate forwarded client IP headers. Review and restrict automatic login mappings to prevent IP spoofing. Update Joomla to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64797. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart