CVE-2026-48908 is a critical-severity vulnerability, listed in the CISA KEV catalog. AttackerView checks SP Page Builder sites for it with a live exploit check.
Detects SP Page Builder for Joomla installations vulnerable to unauthenticated arbitrary file upload leading to remote code execution. In all versions up to and including 6.6.1, the site-side asset controller exposes its tasks with no access-control gate, so the asset.uploadCustomIcon task accepts an icon-font ZIP from any unauthenticated visitor. The IcoMoon import branch recursively copies the attacker-controlled fonts directory into the web-served media tree with no extension filter, so a fonts/shell.php member lands under the web root and executes. The verifier uploads an icon-font ZIP that smuggles a PHP file printing a per-run canary computed from two constants, then fetches the extracted file and confirms the arithmetic result came back, proving server-side code execution rather than mere file persistence. CVSS 9.8, CISA KEV. Upgrade to SP Page Builder 6.6.2 or later.
Is your app exploitable through CVE-2026-48908?
Scan your domain free