What is CVE-2026-65879?
An unauthenticated mail relay vulnerability exists in the SP Page Builder extension for Joomla (versions before 6.7.1) due to a hardcoded, product-wide secret. This flaw allows attackers to forge the 'mail from' address of forms. Immediate update of the SP Page Builder extension to the latest version is recommended.
Azərbaycanca: Joomla üçün SP Page Builder əlavəsində (6.7.1-dən əvvəlki versiyalarda) məhsul səviyyəsində kodlaşdırılmış gizli açar vasitəsilə autentifikasiya olunmamış mail relay zəifliyi aşkarlanıb. Bu boşluq təcavüzkara formalardakı 'mail from' ünvanını saxtalaşdırmağa imkan verir. Dərhal SP Page Builder əlavəsini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of the SP Page Builder extension are affected by CVE-2026-65879?
Versions of the SP Page Builder extension for Joomla before 6.7.1 are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-65879?
An attacker can forge the 'mail from' address of forms.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.