---
schema: 1
kind: vulnerability
title: "CVE-2026-48908 / CVE-2026-56290 — two Joomla page-builder extensions hit CISA KEV the same day for unauth file-upload RCE zero-days"
headline: "Two Joomla page-builder extensions (SP Page Builder, Page Builder CK) hit KEV for unauth file-upload RCE zero-days"
summary: >
  CISA added CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Joomlack Page Builder CK) to KEV on 7 July — both unauthenticated arbitrary-file-upload-to-RCE flaws, both already exploited as zero-days on Joomla sites. Any Joomla estate running third-party page-builder add-ons should patch immediately and hunt for planted Super Administrator accounts and web shells.
discovered_at: "2026-07-08T20:35:00Z"
event_date: 2026-07-07
run_id: 2026-07-08T2009Z-intel
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - cisa-kev
  - zero-day
  - rce
  - pre-auth
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - technology
entities: []
cves:
  - id: CVE-2026-48908
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
    affected: "SP Page Builder ≤ 6.6.1"
    fixed: "6.6.2"
  - id: CVE-2026-56290
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
    affected: "Page Builder CK ≤ 3.5.10"
    fixed: "3.6.0 (back-ports 3.1.1 / 3.4.10)"
sources:
  - url: "https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/"
    publisher: "mySites.guru"
    date: "2026-07-08"
    role: primary
  - url: "https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/"
    publisher: "mySites.guru"
    date: "2026-07-07"
    role: primary
  - url: "https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html"
    publisher: "The Hacker News"
    date: "2026-07-08"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Already exploited in the wild. The payload plants a hidden Super Administrator account, usually with an @secure.local email."
    publisher: "mySites.guru"
  - quote: "CVE-2026-48908, on the other hand, is said to have been exploited as a zero-day to upload a PHP file by means of an HTTP POST request to the 'index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon' endpoint."
    publisher: "The Hacker News"
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Update SP Page Builder to ≥ 6.6.2 and Page Builder CK to ≥ 3.6.0 (or the 3.1.1 / 3.4.10 back-ports) on every Joomla site running them."
  - "Hunt for newly created Joomla Super User / Super Administrator accounts (especially @secure.local addresses) and web shells written under the site web root; patching the entry point does not remove an already-planted admin account."
migrated_from: null
---

Two unrelated third-party Joomla page-builder extensions were both added to CISA KEV on 7 July 2026 for near-identical unauthenticated file-upload-to-RCE flaws, both already exploited as zero-days. CVE-2026-48908 (JoomShaper SP Page Builder, CVSS 10.0, CWE-434) sits in the component's `asset.uploadCustomIcon` task, reachable at `index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon` with no authentication and no file-type validation, affecting versions through 6.6.1 (fixed 6.6.2); mySites.guru observed live attacks planting hidden Super Administrator accounts (typically `@secure.local`) for persistence surviving the entry-point patch ([mySites.guru, 2026-07-08](https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/)). CVE-2026-56290 (Joomlack Page Builder CK, CVSS 10.0, CWE-284) is a front-end upload handler that validated only a CSRF token — no authentication, no authorization — and accepted an attacker-controlled destination folder and filename including the extension, letting a PHP file be written and executed anywhere web-accessible; it affects up to 3.5.10, fixed in 3.6.0 with back-ports to 3.1.1 (Joomla 3) and 3.4.10 (Joomla 4), and the vendor's own suspect-content tooling flagged a live web shell within hours of the fix landing ([mySites.guru, 2026-07-07](https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/)). The Hacker News corroborates both as KEV-listed and actively exploited ([The Hacker News, 2026-07-08](https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html)). **Defender takeaway:** both extensions are common on small-business, municipal and public-sector Joomla sites across the EU; the transferable lesson is the recurring class — an unauthenticated third-party component endpoint that accepts a file with no type/ownership check — so inventory every page-builder / gallery / form add-on in a Joomla estate, not just these two, and watch access logs for POSTs to component upload tasks returning 200 followed by a GET to a newly-named file.
