Knox CVE Database
/
CVE-2026-48908
Critical
9.8

CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Added to the CISA KEV catalog:
July 7, 2026

Overview

SP Page Builder, a widely used page-builder extension for Joomla, contains an unrestricted file upload flaw in versions up to and including 6.6.1. The component's icon upload endpoint accepts PHP files from unauthenticated requesters, giving an attacker immediate remote code execution on the web server. Active exploitation has been observed: attackers are using this access to plant hidden Super Administrator accounts and persistent PHP backdoors, leaving a foothold that survives patching the original entry point.

Vulnerability details

Affected vendor
JoomShaper
Affected product
SP Page Builder
Weakness type (CWE)
CWE-434

CWE-434 (Unrestricted Upload of File with Dangerous Type) occurs when an application accepts file uploads without validating the file's type or content, and stores the result in a location the web server will execute. In SP Page Builder, the controller task asset.uploadCustomIcon exposes this pattern with no authentication gate: the endpoint accepts any file, including PHP scripts, and places it where the Joomla web root can serve it. The missing type check and missing authentication requirement together collapse two independent defenses simultaneously.


An attacker sends a crafted HTTP POST to index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon containing a PHP web shell as the upload payload. No credentials or session token are required. Once the shell is stored, the attacker requests it directly to execute arbitrary commands on the server. Observed post-exploitation activity includes creation of hidden Super Administrator accounts bearing @secure.local email addresses and installation of PHP file manager backdoors at multiple locations for persistence, meaning the attacker retains access even after the vulnerable endpoint is closed.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review Joomla user records for Super Administrator accounts with @secure.local email addresses or plausible-sounding names such as 'Web Editor' or 'Admin Backup' that do not correspond to known staff — these are the documented post-exploitation indicator for this campaign.
  • Audit web server access logs for POST requests to index.php where the query string contains option=com_sppagebuilder and task=asset.uploadCustomIcon, particularly from sources with no prior authenticated session in the same log window.
  • Scan the Joomla web root and subdirectories for recently created PHP files outside the normal extension file set, especially file manager scripts, which the advisory identifies as a persistence mechanism placed in multiple locations.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 10, 2026

Additional hardening

  • Upgrade SP Page Builder to version 6.6.2 or later on every affected Joomla installation. The advisory notes that subsequent releases address additional unrelated flaws, so consult the vendor advisory in References for the current recommended release line.
  • Apply a WAF or ModSecurity rule blocking POST requests to the asset.uploadCustomIcon endpoint (option=com_sppagebuilder&task=asset.uploadCustomIcon) as a compensating control on sites that cannot be patched immediately.
  • After patching, audit all Joomla Super Administrator accounts and remove any with @secure.local email addresses or unrecognized names, then scan the web root for PHP files created during the exposure window before treating the site as clean.
  • Restrict network access to the Joomla admin interface and limit public exposure of the front-end to known IP ranges where operationally feasible, reducing the attack surface for unauthenticated endpoint abuse.

Key dates

Published (NVD)
June 20, 2026
Added to CISA KEV
July 7, 2026
Remediation deadline
July 10, 2026
Last updated
July 8, 2026

References

Frequently asked questions

Does CVE-2026-48908 affect my FedRAMP authorization?

If JoomShaper SP Page Builder runs inside your authorization boundary, CVE-2026-48908 is a direct concern for your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog, with a remediation deadline of July 10, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-48908?

Knox does not patch JoomShaper SP Page Builder on your behalf. Under the FedRAMP shared-responsibility model, remediating that software is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. The patch is yours to apply; maintaining a compliant posture while you apply it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-48908. Exposure surfaces during ongoing monitoring rather than only when an assessor reviews your boundary. That shift means you have time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-48908 isn't remediated by July 10, 2026?

If CVE-2026-48908 is not remediated by July 10, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and preserves the agency relationship.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting