CVE-2026-63048: Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2
Published Jul 22, 2026
·Updated
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
Affected Software
1 affected component
Joomla Page Builder CK<3.6.2
Event History
Jul 22, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63048?
CVE-2026-63048 has a critical severity score of 9.4 as per the CVSS v4.0 standards.
2
How do I fix CVE-2026-63048?
To address CVE-2026-63048, update the Joomla Extension Page Builder CK to version 3.6.2 or later.
3
What type of vulnerability is CVE-2026-63048?
CVE-2026-63048 is categorized as a malicious file upload vulnerability due to improper access control.
4
What can be exploited in CVE-2026-63048?
CVE-2026-63048 can be exploited to perform authenticated arbitrary file uploads, which may lead to remote code execution.
5
Which software is affected by CVE-2026-63048?
The vulnerability affects the Joomla Extension Page Builder CK version prior to 3.6.2.