CVE-2026-63048
The Joomla extension Page Builder CK before version 3.6.2 allows authenticated users to upload arbitrary files, which can lead to remote code execution. This flaw is caused by improper access control and is rated as critical with a CVSS score of 9.4.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Joomla sites that use the Page Builder CK extension in versions earlier than 3.6.2, particularly administrators who can authenticate to the extension.
Real-world impact
An attacker who can log into the Joomla site and access the vulnerable extension can upload malicious files that the server will execute, giving the attacker full control over the web server and its data.
Why this severity
The CVSS score of 9.4 reflects the high impact of remote code execution, the low attack complexity, and the requirement for only low privileges. The vulnerability allows attackers to execute code with the web server’s privileges, leading to complete compromise.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources