What is CVE-2026-63048?
CVE-2026-63048 is an improper access control vulnerability in the Page Builder CK extension for Joomla. It allows authenticated arbitrary file upload in versions before 3.6.2, leading to Remote Code Execution (RCE). Users should update the extension immediately.
Azərbaycanca: CVE-2026-63048 Joomla üçün Page Builder CK genişlənməsində aşkarlanmış boşluqdur. 3.6.2 versiyasından əvvəlki versiyalarda autentifikasiya olunmuş istifadəçiyə ixtiyari fayl yükləməyə imkan verir ki, bu da uzaqdan kod icrasına (RCE) səbəb ola bilər. Genişlənməni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which extension does CVE-2026-63048 affect and what is the main risk?
This vulnerability affects the Page Builder CK extension for Joomla. It allows authenticated arbitrary file upload, which can lead to Remote Code Execution (RCE).
To which version should Page Builder CK be updated to protect against CVE-2026-63048?
The Page Builder CK extension should be updated to version 3.6.2 or later, as the vulnerability exists in versions prior to 3.6.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.