What is CVE-2026-65878?
CVE-2026-65878 is an authenticated arbitrary file deletion vulnerability in the SP Page Builder extension for Joomla. Versions before 6.7.1 contain improper path validation and ACL checks in the media manager, leading to a file deletion vector. Users should immediately update to version 6.7.1 or later.
Azərbaycanca: CVE-2026-65878 Joomla üçün SP Page Builder əlavəsində autentifikasiya olunmuş ixtiyari fayl silmə zəifliyidir. 6.7.1 versiyasından əvvəlki versiyalarda media menecerində düzgün olmayan yol yoxlaması və ACL nəzarəti fayl silmə vektoruna səbəb olur. İstifadəçilər dərhal 6.7.1 və ya daha yeni versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: joomshaper.com
FAQ2
Which platform and component does CVE-2026-65878 affect?
This vulnerability was found in the SP Page Builder extension for Joomla.
What should I do to protect against CVE-2026-65878?
You should immediately update the SP Page Builder extension to version 6.7.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.