Joomla and SP Page Builder, a critical flaw with the highest possible score
Use Joomla and build pages with SP Page Builder? You have something urgent to deal with. CERT Polska warns of a flaw that has been given the maximum possible threat score, 10 out of 10.
What the problem is
The vulnerability (CVE-2026-48908) lets an attacker without logging in upload and run their own malicious script on the server. The culprit is the component responsible for uploading icons, which did not properly check who was uploading which file.
This flaw is not theoretical, it is being actively exploited in attacks. The result is often a full takeover of the site or server.
After a break-in, attackers usually leave themselves hidden administrator accounts and persistent back doors, and can also read the Joomla configuration file with the database credentials. That means an update alone may not be enough, you also have to check whether someone has already got in.
Who it affects and what to do
At risk are all SP Page Builder versions from 1.0.0 to 6.6.1 inclusive. The safe version is 6.6.2 or newer.
- Update the extension to version 6.6.2 or newer, ideally right away.
- If you cannot update immediately, the vendor has released an official patch.
- After updating, be sure to check whether the site has already been compromised.
What to look for when verifying:
- unexpected PHP files in the media and icon directories,
- new, unauthorised administrator accounts,
- suspicious PHP files in the
images,mediaortmpfolders.
If these points sound like a foreign language to you, do not worry, that is what we are here for. We will update the extension, review the site for signs of a break-in and clean up if someone managed to leave something behind.
Source: CERT Polska advisory 104/2026