All verified exploits

CVE-2026-48908 Unauthenticated Arbitrary File Upload (RCE)

CVE-2026-48908 is a critical-severity vulnerability, listed in the CISA KEV catalog. AttackerView checks SP Page Builder sites for it with a live exploit check.

Deterministic critical SP Page Builder CISA KEV Added cve-verified-cve-2026-48908

Is my site vulnerable to CVE-2026-48908?

Detects SP Page Builder for Joomla installations vulnerable to unauthenticated arbitrary file upload leading to remote code execution. In all versions up to and including 6.6.1, the site-side asset controller exposes its tasks with no access-control gate, so the asset.uploadCustomIcon task accepts an icon-font ZIP from any unauthenticated visitor. The IcoMoon import branch recursively copies the attacker-controlled fonts directory into the web-served media tree with no extension filter, so a fonts/shell.php member lands under the web root and executes. The verifier uploads an icon-font ZIP that smuggles a PHP file printing a per-run canary computed from two constants, then fetches the extracted file and confirms the arithmetic result came back, proving server-side code execution rather than mere file persistence. CVSS 9.8, CISA KEV. Upgrade to SP Page Builder 6.6.2 or later.

Is your app exploitable through CVE-2026-48908?

Scan your domain free