Vulnerabilities & Exploits · Zero-Day Exploit

Joomla Plugin Upload Feature Becomes Server Takeover Path

A convenience upload feature in SP Page Builder now acts as a server takeover path. An unauthenticated attacker can abuse the custom-icon upload function to place PHP on the host and run code, so patching alone does not rule out a hidden shell or stolen admin access already left behind.

CSIRT-ITA says CVE-2026-48908 is being actively exploited in SP Page Builder, and the vendor has fixed it in 6.6.2. The flaw affects versions before 6.6.2 and comes from weak access checks on the icon upload path, which lets remote users upload crafted PHP instead of an image.

The follow-on risk is persistence. The advisory calls out unknown Super Administrator accounts, suspicious PHP files, and compromised Joomla, SSH, and FTP credentials as signs the attacker may still be inside after the update.

1 source · Jun 26

CVE-2026-48908

NVD KEV

Known exploited · CISA KEV

EPSS 15% (97th percentile).

CISA federal remediation date Jul 10

Timeline

Sources

Part of the PlainSec briefing for 2026-06-26

Every edition of this story: Joomla Plugin Upload Feature Becomes Server Takeover Path

More from today