Joomla Plugin Upload Feature Becomes Server Takeover Path

A convenience upload feature in SP Page Builder now acts as a server takeover path. An unauthenticated attacker can abuse the custom-icon upload function to place PHP on the host and run code, so patching alone does not rule out a hidden shell or stolen admin access already left behind. CSIRT-ITA says CVE-2026-48908 is being actively exploited in SP Page Builder, and the vendor has fixed it in 6.6.2. The flaw affects versions before 6.6.2 and comes from weak access checks on the icon upload path, which lets remote users upload crafted PHP instead of an image. The follow-on risk is persistence. The advisory calls out unknown Super Administrator accounts, suspicious PHP files, and compromised Joomla, SSH, and FTP credentials as signs the attacker may still be inside after the update.

Part of the PlainSec briefing for 2026-06-27

Sources