discovered 03 Aug 2026
CVE-2026-48908-PoC
→ View on GitHubCVE-2026-48908-PoC is a proof-of-concept exploit for a critical unauthenticated remote code execution vulnerability in the SP Page Builder component for Joomla. This tool leverages the improper access control in the asset.uploadCustomIcon task to upload malicious files to a publicly accessible directory, ultimately enabling an attacker to execute arbitrary code on the target server. Notable features include an adaptive payload mechanism that tests various file extensions and .htaccess file injections to bypass server restrictions, as well as cleanup functionality to remove uploaded artifacts after exploitation.