Skip to main content
kcheung
Staff
Staff
September 2, 2026

FortiGuard Outbreak Alert: Joomla SP Page Builder RCE

  • September 2, 2026
  • 0 replies
  • 24 views

Description

Joomla SP Page Builder is a drag-and-drop page builder extension for Joomla that lets you create responsive, professional websites without coding.

CVE-2026-48908 is an unrestricted file upload vulnerability in the SP Page Builder extension for Joomla with the asset.uploadCustomIcon controller task exposed without authentication which allows an unauthenticated remote attacker to upload an arbitrary PHP file to the web root and execute arbitrary code on the server.

The following versions of SP Page Builder extension for Joomla is vulnerable to CVE-2026-48908:

  • < 6.6.2

CVE ID

CVE-2026-48908

NDR Cloud Detection Rule

FortiNDR Cloud v26.3+

Detection Rule Name

Category

Primary MITRE ID

FortiGuard Outbreak Alert: Joomla SP Page Builder Arbitrary File Upload - CVE-2026-48908

Attack: Exploitation

T1190 - Exploit Public-Facing Application

Playbook

N/A

Threat Hunting

FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for "Joomla SP Page Builder RCE" related activities.

IOC source: Joomla SP Page Builder RCE | Indicators of Compromise

All IOCs relating to "Joomla SP Page Builder RCE" have been added to Threat Intelligence Intel.

Suricata Coverage

Customers can create custom investigation/detections using the DPI and Suricata signatures below:

DPI:

DPI Vulnerability ID (dpi_vuln_id)

DPI Alert Signature

61172

Joomla!.SP.Page.Builder.Arbitrary.File.Upload

Suricata:

Suricata Signature ID

Suricata Signature

100109828

ATR EXPLOITATION Joomla! SP Page Builder Arbitrary File Upload - CVE-2026-48908

Other Fortinet Products

For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to Joomla SP Page Builder RCE.

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!