Authenticated Arbitrary File Deletion in SP Page Builder by JoomShaper
CVE-2026-65878

8.3HIGH

Key Information:

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65878?

The SP Page Builder, a widely used Joomla extension developed by JoomShaper, is susceptible to an authenticated arbitrary file deletion vulnerability. This issue arises from improper path validation and insufficient access control list (ACL) checks, allowing unauthorized users with valid credentials to delete files through the media manager. This weakness could lead to significant data loss and manipulation, posing a severe risk to Joomla sites relying on this extension. Users are urged to upgrade to version 6.7.1 or later to mitigate this vulnerability.

Affected Version(s)

SP Page Builder extension for Joomla 1.0.0-6.7.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.