ADVISORY SUMMARY
JoomShaper SP Page Builder contains a CVSS 10.0 unrestricted file upload vulnerability allowing unauthenticated users to upload and execute arbitrary PHP code. It was exploited as a zero-day via HTTP POST to the 'index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon' endpoint, resulting in new rogue Super User accounts being created on victim Joomla sites. The threat activity is assessed as opportunistic and financially motivated.
AFFECTED SYSTEMS
MITIGATION GUIDANCE
Update SP Page Builder to version 6.6.2 or later immediately. Audit the Joomla installation for unexpected Super User accounts created after any plausible exploitation window and remove them. Restrict write permissions on the upload directories if patching is delayed.
DETECTION SIGNATURES
Search web server access logs for POST requests to 'index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon'. Hunt for newly created .php files in Joomla asset/upload directories with recent timestamps. Audit administrator-level accounts for unexpected additions.
REFERENCES
- → https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
- → https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
- → https://nvd.nist.gov/vuln/detail/CVE-2026-48908
- → https://extensions.joomla.org/extension/sp-page-builder/