CVE-2026-62414
A Joomla extension called Page Builder CK has a critical flaw that lets anyone view restricted page lists on the front end. The issue is due to improper access control and is present in versions older than 3.6.2. Users should update the extension to fix the problem.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Joomla users who have the Page Builder CK extension installed, especially those using versions older than 3.6.2.
Real-world impact
An attacker could see lists of pages that should be hidden, potentially exposing sensitive content or planning further attacks.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is exploitable over the network with no authentication, can reveal confidential information, and has a high impact on confidentiality and integrity.
What to do about it
- 01Upgrade Page Builder CK to version 3.6.2 or later.
NVD description
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 9d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.