PatchSiren cyber security CVE debrief
CVE-2026-63048 joomlack.fr CVE debrief
The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to Remote Code Execution (RCE). This critical vulnerability has a CVSS score of 9.4 and is classified as CRITICAL. Users of Joomla extension Page Builder CK should be aware of this vulnerability and take immediate action to protect their installations. The vulnerability allows authenticated users to upload arbitrary files, which can lead to Remote Code Execution (RCE).
- Vendor
- joomlack.fr
- Product
- Page Builder CK extension for Joomla
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of Joomla extension Page Builder CK, administrators, security teams, and vulnerability management teams should be aware of this vulnerability and take immediate action to protect their installations. This vulnerability can lead to Remote Code Execution (RCE) and has a CVSS score of 9.4, classified as CRITICAL.
Technical summary
CVE-2026-63048 is a critical vulnerability in the Joomla extension Page Builder CK, allowing authenticated users to upload arbitrary files, which can lead to Remote Code Execution (RCE). The vulnerability has a CVSS score of 9.4 and is classified as CRITICAL. This vulnerability affects Joomla extension Page Builder CK and can be exploited by authenticated users.
Defensive priority
High
Recommended defensive actions
- Update Page Builder CK to the latest version
- Restrict file uploads to only trusted users
- Monitor for suspicious file upload activity
- Implement a Web Application Firewall (WAF) to detect and prevent attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record was published on 2026-07-22T08:16:24.063Z and has not been modified since then. The NVD entry is currently Received. This information is based on the CVE record and NVD entry. Users should verify the affected scope and severity with the official sources. The vulnerability affects Joomla extension Page Builder CK, allowing authenticated users to upload arbitrary files, which can lead to Remote Code Execution (RCE).
Official resources
-
CVE-2026-63048 CVE record
CVE.org
-
CVE-2026-63048 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T08:16:24.063Z and has not been modified since then. The NVD entry is currently Received.