All CVEs View on NVD
CVE-2026-64797
UNKNOWN
Published 2026-07-22 · Source security@joomla.org
Description
IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
CWE-290

