Critical (CVSS v4: 10.0) — Proof-of-concept exploit for unauthenticated remote code execution in SP Page Builder (
com_sppagebuilder) for Joomla.
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-48908 |
| Severity | Critical |
| CVSS v4 Score | 10.0 |
| Weakness | CWE-284 (Improper Access Control) → Unauthenticated File Upload |
| Component | SP Page Builder (com_sppagebuilder) for Joomla |
| Affected Versions | 1.0.0 – 6.6.1 |
| Fixed Version | 6.6.2 |
| Privileges Required | None (pre‑authentication) |
| User Interaction | None |
| Attack Vector | Network |
| Impact | Full system compromise (RCE) |
SP Page Builder exposes the controller task asset.uploadCustomIcon to handle uploading a custom icon‑font package:
index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon
In vulnerable versions, this task is reachable without authentication and without a valid CSRF token. It accepts a ZIP archive (multipart field custom_icon) and extracts its contents into a publicly accessible directory under the web root:
/media/com_sppagebuilder/assets/iconfont/<name>/
Because the endpoint is accessible pre‑authentication and the extracted files land in a browsable location, an attacker can upload arbitrary files and execute PHP code by requesting them over HTTP.
This exploit defeats common server‑side filename filters using:
- Case‑sensitive blocklist bypass – The filter rejects lower‑case
.php,.phtml,.phar, etc., but does not normalise case, so.PHPand other mixed‑case variants are accepted. - Valid icon‑font structure – The exploit packages a valid
selection.json,style.css, andfonts/<name>.ttfso the upload is accepted. - Shell placement – A PHP web shell is written to
fonts/shxt.{ext}within the extracted archive.
- Multi‑threaded scanning and exploitation (configurable thread count)
- Automatic URL fixing – appends the required endpoint path automatically
- Dual extension support – attempts
.phpand.PHPvariants - Shell verification – checks that the uploaded shell is accessible and functional
- Result logging – saves successful shell URLs to
result.txt - Progress tracking – displays real‑time status and statistics
- Python 2.7
requestslibrary
git clone https://github.com/Jenderal92/CVE-2026-48908
cd CVE-2026-48908
pip install requestsBasic Usage
python2 CVE-2026-48908.py list.txtWith Custom Thread Count
python2 CVE-2026-48908.py list.txt 20Input File Format
list.txt should contain one target URL per line:
https://example.com
http://target-site.com/joomla
https://192.168.1.100/joomla
Output
· Successful shell URLs are appended to result.txt · Each line contains the full URL to the uploaded PHP shell
⚙️ How It Works
- URL Fixing – Automatically appends index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon if not already present.
- ZIP Construction – Creates a valid icon‑font ZIP archive containing the PHP shell at fonts/shxt.{ext}.
- Upload – Sends the ZIP via multipart POST to the vulnerable endpoint.
- Verification – Checks if the shell is accessible and returns the expected output (presence of "Upload").
- Logging – Saves successful shell URLs to result.txt.
Shell Payload
The embedded shell provides:
· Server environment information (php_uname()) · File upload interface for uploading additional files · Success / failure feedback
🛡️ Mitigation
· Upgrade SP Page Builder to version 6.6.2 or newer. · Audit upload directories for unauthorised files: · /media/com_sppagebuilder/assets/iconfont/ · Remove any unexpected PHP files found in those directories. · Review server logs for suspicious POST requests to asset.uploadCustomIcon. · Deploy a Web Application Firewall (WAF) to block such requests.
This tool is for educational and authorised security testing purposes only.
Unauthorised access to computer systems is illegal. The authors assume no responsibility for any misuse or damage caused by this tool. Only use this on systems you own or have explicit written permission to test.
More Disclaimer You Can see the disclaimer on the cover of Jenderal92. You can check it HERE !!!
📚 References
· Censys Advisory · NVD Entry · JoomShaper Security Announcement
📄 License
This project is for educational and research purposes only. Use at your own risk.