VULNERABILITY OVERVIEW
The asset.uploadCustomIcon endpoint in SP Page Builder performs no authentication checks and no file-type validation, allowing unauthenticated attackers to upload PHP webshells to web-accessible directories via a single HTTP POST request and achieve full RCE. Exploitation was observed in the wild as a zero-day before the patch shipped on June 14; post-exploitation activity includes creation of hidden Joomla Super Administrator accounts and persistent PHP file-manager backdoors. Approximately 194,793 web properties are estimated to load the affected component; public PoC is available and botnet scanning is confirmed active. CISA added to KEV July 7.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
AFFECTED VERSIONS
SP Page Builder versions 1.0.0 through 6.6.1 (all versions prior to 6.6.2)CITATIONS
- → https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
- → https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
- → https://www.ionix.io/threat-center/cve-2026-48908/
- → https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html