DIRAS TAKE
High urgency: CISA added CVE-2026-48908 to its Known Exploited Vulnerabilities catalog with a July 10, 2026 remediation deadline, so treat internet-facing installations as emergency fixes and follow vendor guidance immediately.
What is CVE-2026-48908?
Unauthenticated attackers can upload arbitrary files to JoomShaper SP Page Builder and achieve remote code execution; this is tracked as CVE-2026-48908. The flaw affects SP Page Builder 1.x versions from 1.0.0 through 6.6.1 and requires no user authentication — an attacker only needs network access to a site running the vulnerable extension to deliver a malicious file that can be executed on the server. Public exploit code exists for this vulnerability. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of JoomShaper SP Page Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0.0-6.6.1 |
Is CVE-2026-48908 being exploited?
CISA added CVE-2026-48908 to the Known Exploited Vulnerabilities catalog on 2026-07-07, and US federal agencies were required to address it by 2026-07-10. Public exploit code for the vulnerability is available.
How to fix CVE-2026-48908
- Follow JoomShaper vendor guidance and apply any provided mitigations immediately.
- If no vendor patch is available, remove or disable SP Page Builder on exposed systems until fixed versions are released.
- Restrict access to the Joomla site: block or filter upload endpoints, restrict admin interfaces to trusted IPs, and limit public write access.
- Monitor web and application logs for suspicious uploads and indicators of PHP file execution; investigate and restore from clean backups if compromise is detected.
Frequently asked questions
Is CVE-2026-48908 being actively exploited?
There are no public reports in the provided facts that confirm active exploitation, but SP Page Builder has public exploit code available and CISA added the issue to its KEV catalog.
Which SP Page Builder versions are affected by CVE-2026-48908?
SP Page Builder 1.x releases from 1.0.0 through 6.6.1 are listed as affected by CVE-2026-48908.
Is there a patch for CVE-2026-48908?
No fixed release is listed in the provided facts; vendor-supplied fixed versions are not available in the affected[] data.
Does CVE-2026-48908 require authentication?
No — the vulnerability allows unauthenticated users to upload arbitrary files to SP Page Builder, enabling remote code execution without a valid account.
References
- nvd.nist.gov/vuln/detail/CVE-2026-48908
- cve.org/CVERecord?id=CVE-2026-48908
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908
- joomshaper.com/page-builder
- All JoomShaper CVEs on CVE Radar
- CVEs published in September 2026