Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

[KEV] CVE-2026-48908 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-48908 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-48908 is an unrestricted file upload vulnerability in JoomShaper SP Page Builder, a Joomla extension, that allows unauthenticated remote attackers to upload and execute arbitrary PHP files on the host server.

Technical Detail

The flaw exists in SP Page Builder's file upload handling, which fails to enforce adequate restrictions on the type or content of uploaded files for unauthenticated requests. An attacker can submit a malicious PHP file through the vulnerable upload endpoint without any authentication, after which the uploaded file can be accessed and executed directly on the web server, resulting in unauthenticated remote code execution (RCE). Successful exploitation grants the attacker arbitrary command execution in the context of the web server process, enabling full compromise of the hosting environment.

Exploitation Status

CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026. The exploit maturity is rated Operational, meaning functional exploit code capable of reliable exploitation exists and is being used in active attack campaigns, not merely as a proof-of-concept demonstration. Organizations running SP Page Builder should treat this as an immediate, active threat rather than a theoretical risk.

Who Is Targeting This

No confirmed, ATTAX-verified threat actor attribution has been established at this time. Reported (research-inferred, medium confidence): DEEPPANDA, CARBANAK, LOTUSBLOSSOM, AXIOM, and MOONSTONESLEET have each been associated with activity related to this vulnerability, though none of these attributions have been independently confirmed. Motivations for all reported actors are currently unknown. These associations should be treated as investigative leads rather than established attribution.

What To Do

Per CISA's Known Exploited Vulnerabilities catalog, federal agencies subject to BOD 22-01 are required to remediate this vulnerability immediately given its confirmed active exploitation status. All organizations should apply the vendor-supplied patch for SP Page Builder as the highest priority action. If an immediate patch cannot be applied, administrators should disable the SP Page Builder component entirely until remediation is possible, and restrict web server write permissions to directories accessible via public URLs. Detection efforts should focus on monitoring web server logs for unexpected PHP file uploads, newly created PHP files in upload or media directories, and anomalous outbound connections or command execution originating from the web server process. Given the unauthenticated nature of the exploit, internet-facing Joomla installations with SP Page Builder installed should be considered at high risk and prioritized accordingly. The CVSS score of 0.0 currently assigned to this CVE does not reflect the actual severity of the vulnerability and should not be used to deprioritize remediation given confirmed active exploitation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →