SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-63048

CRITICAL · CVSS 9.4 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Page Builder CK extension for Joomla versions prior to 3.6.2 is susceptible to improper access control, allowing authenticated users to upload arbitrary files, which can lead to remote code execution (RCE). Organizations using this extension should prioritize patching to mitigate the risk of unauthorized access and potential exploitation. This vulnerability is particularly critical for sites that handle sensitive data or have a high user interaction level.

CVE
CVE-2026-63048
Severity
CRITICAL
CVSS
9.4
EPSS
0.23%

Original NVD Description

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.