JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
SP Page Builder, a widely used page-builder extension for Joomla, contains an unrestricted file upload flaw in versions up to and including 6.6.1. The component's icon upload endpoint accepts PHP files from unauthenticated requesters, giving an attacker immediate remote code execution on the web server. Active exploitation has been observed: attackers are using this access to plant hidden Super Administrator accounts and persistent PHP backdoors, leaving a foothold that survives patching the original entry point.
CWE-434 (Unrestricted Upload of File with Dangerous Type) occurs when an application accepts file uploads without validating the file's type or content, and stores the result in a location the web server will execute. In SP Page Builder, the controller task asset.uploadCustomIcon exposes this pattern with no authentication gate: the endpoint accepts any file, including PHP scripts, and places it where the Joomla web root can serve it. The missing type check and missing authentication requirement together collapse two independent defenses simultaneously.
An attacker sends a crafted HTTP POST to index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon containing a PHP web shell as the upload payload. No credentials or session token are required. Once the shell is stored, the attacker requests it directly to execute arbitrary commands on the server. Observed post-exploitation activity includes creation of hidden Super Administrator accounts bearing @secure.local email addresses and installation of PHP file manager backdoors at multiple locations for persistence, meaning the attacker retains access even after the vulnerable endpoint is closed.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
@secure.local email addresses or plausible-sounding names such as 'Web Editor' or 'Admin Backup' that do not correspond to known staff — these are the documented post-exploitation indicator for this campaign.index.php where the query string contains option=com_sppagebuilder and task=asset.uploadCustomIcon, particularly from sources with no prior authenticated session in the same log window.asset.uploadCustomIcon endpoint (option=com_sppagebuilder&task=asset.uploadCustomIcon) as a compensating control on sites that cannot be patched immediately.@secure.local email addresses or unrecognized names, then scan the web root for PHP files created during the exposure window before treating the site as clean.If JoomShaper SP Page Builder runs inside your authorization boundary, CVE-2026-48908 is a direct concern for your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog, with a remediation deadline of July 10, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.
Knox does not patch JoomShaper SP Page Builder on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. The patch is yours to apply; maintaining a compliant posture while you apply it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-48908. Exposure surfaces during ongoing monitoring rather than only when an assessor reviews your boundary. That shift means you have time to act before a finding becomes a formal problem.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-48908 is not remediated by July 10, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and preserves the agency relationship.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









