Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

[KEV] CVE-2026-48908 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-48908 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-48908 is an unrestricted file upload vulnerability in JoomShaper SP Page Builder, a Joomla extension, that allows unauthenticated remote attackers to upload and execute arbitrary PHP files on the host server.

Technical Detail

The flaw exists in SP Page Builder's file upload handling, which fails to enforce adequate restrictions on the type or content of uploaded files for unauthenticated requests. An attacker can submit a malicious PHP file directly to the vulnerable upload endpoint without any authentication, bypassing expected access controls. Successful exploitation results in remote code execution (RCE) under the web server process context, giving the attacker the ability to execute arbitrary commands, access sensitive data, or establish persistent access on the affected host.

Exploitation Status

CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026. The exploit maturity is rated Operational, meaning reliable, functional exploit code exists and is being actively used in attacks rather than existing only as a proof-of-concept. In practice, this level of maturity indicates the vulnerability is accessible to a broad range of threat actors, including less sophisticated opportunistic attackers leveraging automated tooling against internet-exposed Joomla installations running SP Page Builder.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been identified in available intelligence. Given the unauthenticated RCE nature of the vulnerability and its KEV listing, opportunistic mass-scanning activity targeting exposed Joomla sites is a reasonable operational assumption, though no named actor or campaign has been formally attributed.

What To Do

Per CISA's binding operational directive associated with KEV listings, federal agencies are required to apply patches or mitigations by the deadline established upon KEV addition on July 7, 2026. All organizations running JoomShaper SP Page Builder should apply the vendor-supplied patch immediately and treat this as a critical priority given confirmed in-the-wild exploitation. If a patch is not yet available or cannot be applied immediately, restrict or disable the file upload functionality within SP Page Builder and block unauthenticated access to upload endpoints at the web application firewall or server configuration level. Administrators should audit web-accessible directories for recently uploaded PHP files, review web server access logs for anomalous POST requests to upload endpoints, and scan for webshells as indicators of prior compromise. Joomla installations exposed directly to the internet without a WAF or reverse proxy should be treated as high-risk until patched.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →