Access Control Flaw in Joomla Extension SP Page Builder by JoomShaper
CVE-2026-81566
5.1MEDIUM
What is CVE-2026-81566?
The SP Page Builder extension for Joomla contains a critical access control vulnerability that allows unauthorized users to create and overwrite menu items. This occurs due to inadequate authorization checks in the menu item creation process, where the 'save()' method of the com_menus item model is invoked directly. As a result, users lacking permission to edit menu items can manipulate existing entries, potentially compromising site functionality by altering the homepage and other crucial menu items. This highlights the necessity for robust access control implementations in web applications to safeguard user privileges and prevent unauthorized changes.
Affected Version(s)
SP Page Builder (Free and Pro) extension for Joomla 4.0.0 - 6.9.0
