Vulnary
← back to the feed
Critical· 9.4

CVE-2026-63048

The Joomla extension Page Builder CK before version 3.6.2 allows authenticated users to upload arbitrary files, which can lead to remote code execution. This flaw is caused by improper access control and is rated as critical with a CVSS score of 9.4.

publishedJul 22, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.4
critical · how bad it is
exploitation · epss
<1%
13th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 5, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Joomla sites that use the Page Builder CK extension in versions earlier than 3.6.2, particularly administrators who can authenticate to the extension.

02

Real-world impact

An attacker who can log into the Joomla site and access the vulnerable extension can upload malicious files that the server will execute, giving the attacker full control over the web server and its data.

03

Why this severity

The CVSS score of 9.4 reflects the high impact of remote code execution, the low attack complexity, and the requirement for only low privileges. The vulnerability allows attackers to execute code with the web server’s privileges, leading to complete compromise.

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredLow
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →