FortiGuard Outbreak Alert: Joomla SP Page Builder RCE
Description | Joomla SP Page Builder is a drag-and-drop page builder extension for Joomla that lets you create responsive, professional websites without coding. CVE-2026-48908 is an unrestricted file upload vulnerability in the SP Page Builder extension for Joomla with the asset.uploadCustomIcon controller task exposed without authentication which allows an unauthenticated remote attacker to upload an arbitrary PHP file to the web root and execute arbitrary code on the server. The following versions of SP Page Builder extension for Joomla is vulnerable to CVE-2026-48908:
| ||||||||
CVE ID | |||||||||
NDR Cloud Detection Rule | FortiNDR Cloud v26.3+
| ||||||||
Playbook | N/A | ||||||||
Threat Hunting | FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for "Joomla SP Page Builder RCE" related activities. IOC source: Joomla SP Page Builder RCE | Indicators of Compromise All IOCs relating to "Joomla SP Page Builder RCE" have been added to Threat Intelligence Intel. | ||||||||
Suricata Coverage | Customers can create custom investigation/detections using the DPI and Suricata signatures below: DPI:
Suricata:
| ||||||||
Other Fortinet Products | For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to Joomla SP Page Builder RCE. |
