Joomla Page Builder CK 1.0.0-3.6.2 Arbitrary File Upload RCE
CVE-2026-63048 Published on July 22, 2026
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2
The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
Weakness Type
What is an Unrestricted File Upload Vulnerability?
The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
CVE-2026-63048 has been classified to as an Unrestricted File Upload vulnerability or weakness.