Access Control Flaw in Joomla Extension SP Page Builder by JoomShaper
CVE-2026-81566

5.1MEDIUM

What is CVE-2026-81566?

The SP Page Builder extension for Joomla contains a critical access control vulnerability that allows unauthorized users to create and overwrite menu items. This occurs due to inadequate authorization checks in the menu item creation process, where the 'save()' method of the com_menus item model is invoked directly. As a result, users lacking permission to edit menu items can manipulate existing entries, potentially compromising site functionality by altering the homepage and other crucial menu items. This highlights the necessity for robust access control implementations in web applications to safeguard user privileges and prevent unauthorized changes.

Affected Version(s)

SP Page Builder (Free and Pro) extension for Joomla 4.0.0 - 6.9.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.