CVE-2026-48908

CRITICAL KEV

Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-48908 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 7, 2026. EIP tracks 10 public exploits from researchers including papageo75, g0thamRabb1t, cazzysoci.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-48908, an unauthenticated RCE vulnerability in SP Page Builder for Joomla. The exploit leverages a case-sensitive blocklist bypass to upload a malicious ZIP file containing a PHP shell and .htaccess file, achieving remote code execution.

Description

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Exploits (10)

github WORKING POC 1 stars
by papageo75 · pythonremote
https://github.com/papageo75/CVE-2026-48908-PoC

This repository contains a functional exploit for CVE-2026-48908, an unauthenticated RCE vulnerability in SP Page Builder for Joomla. The exploit leverages a case-sensitive blocklist bypass to upload a malicious ZIP file containing a PHP shell and .htaccess file, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SP Page Builder (com_sppagebuilder) for Joomla <= 6.6.1
No auth needed
Prerequisites: Joomla with SP Page Builder <= 6.6.1 · Apache with AllowOverride enabled
mistral-large-3 · analyzed Jun 22, 2026 Full analysis →
github WRITEUP
by g0thamRabb1t · poc
https://github.com/g0thamRabb1t/CVE-2026-48908-joomla-sp-page-builder-detection

This repository provides a detailed technical analysis of CVE-2026-48908, a remote code execution vulnerability in Joomla SP Page Builder. It includes evidence of exploitation (screenshots, logs, and reports) but intentionally omits exploit code, focusing on detection, validation, and mitigation guidance.

Classification
Writeup 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla SP Page Builder (versions vulnerable to CVE-2026-48908)
No auth needed
Prerequisites: Joomla installation with vulnerable SP Page Builder component · Access to the `asset.uploadCustomIcon` endpoint
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →
github WORKING POC
by cazzysoci · pythonremote
https://github.com/cazzysoci/cve-2026-48908

This PoC exploits an arbitrary file upload vulnerability in Joomla's SPPB Page Builder component (CVE-2026-48908) by crafting a malicious ZIP file containing a PHP web shell disguised as an icon font asset. The exploit bypasses extension checks and uploads the shell to a predictable path for remote code execution.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla SPPB Page Builder component (unspecified version)
No auth needed
Prerequisites: Target must have Joomla with SPPB Page Builder component installed · Endpoint `/index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon` must be accessible · PHP execution must be enabled on the server
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/48xxx/CVE-2026-48908.md

The repository contains only a markdown file listing multiple external GitHub repositories and a backup link to an encrypted archive, with no actual exploit code or technical analysis. The external links and encrypted backup are red flags for potential social engineering or malware distribution.

Classification
Suspicious 98%
Attack Type
Rce
Complexity
Trivial
Reliability
Unknown
Target: SP Page Builder extension for Joomla < 6.6.2
No auth needed
Prerequisites: Access to a vulnerable Joomla instance with SP Page Builder < 6.6.2
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
github WORKING POC
by Jenderal92 · pythonpoc
https://github.com/Jenderal92/CVE-2026-48908

This exploit targets an unauthenticated file upload vulnerability in SP Page Builder (Joomla) versions 1.0.0-6.6.1, allowing remote code execution via a crafted ZIP archive containing a PHP web shell. The exploit bypasses case-sensitive filename filters by using mixed-case extensions (.PHP) and verifies shell accessibility post-upload.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SP Page Builder (com_sppagebuilder) for Joomla versions 1.0.0 - 6.6.1
No auth needed
Prerequisites: Target must have SP Page Builder installed (versions 1.0.0-6.6.1) · Endpoint `/index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon` must be accessible · PHP execution must be enabled on the server
mistral-large-3 · analyzed Jul 07, 2026 Full analysis →
github WORKING POC
by bayu06802 · pythonremote
https://github.com/bayu06802/CVE-2026-48908

This exploit targets CVE-2026-48908, an unauthenticated remote code execution vulnerability in SP Page Builder (Joomla) versions ≤6.6.1. It abuses an improper access control flaw in the `asset.uploadCustomIcon` task to upload a malicious ZIP file containing a PHP webshell, achieving code execution via adaptive methods (direct PHP upload or .htaccess bypass).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SP Page Builder (com_sppagebuilder) for Joomla ≤6.6.1
No auth needed
Prerequisites: Target must be running SP Page Builder ≤6.6.1 · PHP execution must be enabled in the upload directory (or AllowOverride permitted for .htaccess) · Web server must allow file uploads to a web-accessible directory
mistral-large-3 · analyzed Jul 05, 2026 Full analysis →
nomisec WORKING POC
by ayiezola · remote
https://github.com/ayiezola/CVE-2026-48908

This repository contains a functional exploit for CVE-2026-48908, targeting an unauthenticated RCE vulnerability in SP Page Builder. The exploit uploads a malicious ZIP file containing a PHP shell, bypasses authentication, and achieves remote code execution via multiple methods (direct PHP extensions or .htaccess manipulation).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SP Page Builder (likely versions before 6.6.2)
No auth needed
Prerequisites: Target running vulnerable SP Page Builder · Network access to the target
mistral-large-3 · analyzed Jun 29, 2026 Full analysis →
github WORKING POC
by 0xBlackash · pythonpoc
https://github.com/0xBlackash/CVE-2026-48908

The repository contains a functional Python exploit for CVE-2026-48908, which targets an unauthenticated file upload vulnerability in SP Page Builder for Joomla (<= 6.6.1). The exploit crafts a malicious ZIP file to upload a PHP webshell, achieving remote code execution (RCE).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SP Page Builder for Joomla (<= 6.6.1)
No auth needed
Prerequisites: Target running vulnerable SP Page Builder version · Network access to the target
mistral-large-3 · analyzed Jun 25, 2026 Full analysis →
nomisec WORKING POC
by ogenich · poc
https://github.com/ogenich/CVE-2026-48908

This repository contains a functional exploit for CVE-2026-48908, targeting SP Page Builder for Joomla. The exploit leverages unauthenticated file upload via the `asset.uploadCustomIcon` task to achieve remote code execution by uploading a malicious ZIP file containing a PHP shell.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SP Page Builder (com_sppagebuilder) for Joomla ≤ 6.6.1
No auth needed
Prerequisites: Target running SP Page Builder ≤ 6.6.1 · Access to the target's web interface
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →
github SUSPICIOUS
by gagaltotal · poc
https://github.com/gagaltotal/CVE-2026-48908-SP-Page-Builder-Joomla

The repository contains only a README with minimal information about CVE-2026-48908, claiming an unauthenticated RCE in SP Page Builder for Joomla, but lacks any technical details, exploit code, or proof-of-concept. The absence of substantive content and reliance on vague claims suggest a potential lure.

Classification
Suspicious 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: SP Page Builder for Joomla (version unspecified)
No auth needed
Prerequisites: none specified
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0157
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-07
VulnCheck KEV 2026-06-15
ENISA EUVD EUVD-2026-38110
CWE
CWE-434
Status published
Products (2)
joomshaper.net/SP Page Builder extension for Joomla 1.0.0-6.6.1
ollyo/sp_page_builder < 6.6.2
Published Jun 20, 2026
KEV Added Jul 07, 2026
Tracked Since Jun 20, 2026