Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-48908-joomla-sp-page-builder-detection — Validates CVE-2026-48908 in Joomla SP Page Builder with unauthorized icon upload leading to PHP code execution. Includes auditd/PCAP evidence, event timeline, and SOC detection recommendations for defensive research. | Kitploit
Tools/GitHubGitHub/g0thamrabb1t/cve-2026-48908-joomla-sp-page-builder-detection
Vulnerability AnalysisExploitationWeb Application ExploitationForensicsWeb SecurityPenetration TestingPapers & ResearchLearning & EducationIncident Response
GitHubg0thamrabb1t/cve-2026-48908-joomla-sp-page-builder-detection

CVE-2026-48908-joomla-sp-page-builder-detection

Validates CVE-2026-48908 in Joomla SP Page Builder with unauthorized icon upload leading to PHP code execution. Includes auditd/PCAP evidence, event timeline, and SOC detection recommendations for defensive research.

View Repository
142 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-48908 — Joomla SP Page Builder Validation and Detection

Laboratory validation of CVE-2026-48908 in the Joomla SP Page Builder component, focused on technical evidence, event reconstruction, and defensive detection opportunities.

The repository documents a controlled test in which the SP Page Builder asset.uploadCustomIcon endpoint accepted uploaded icon archives that resulted in PHP artifacts being written under the Joomla media directory. Invoking the uploaded PHP file over HTTP led to command execution as the web server process user. The resulting HTTP, file, process, authentication, and network activity was captured using Apache container logs, Linux auditd, tcpdump, Docker telemetry, file-change polling, and screenshots from the Windows host.

[!IMPORTANT] This repository contains reports and screenshots only. Offensive exploit code, payload source, raw PCAP files, and raw host evidence packages are intentionally not included. The material is intended for vulnerability validation, SOC engineering, detection development, incident-response preparation, and authorized research.

Reports

  • English validation report
  • Polish validation report

Both reports contain the full test methodology, evidence excerpts, event timeline, file-change evidence, network indicators, mitigation guidance, audit recommendations, and example SIEM logic.

Repository structure

.
├── README.md
├── SHA256SUMS.txt
├── reports/
│   ├── CVE-2026-48908_SP_Page_Builder_detection_EN.pdf
│   └── CVE-2026-48908_SP_Page_Builder_detection_PL.pdf
└── screenshots/
    ├── 01_poc_upload_and_code_execution.png
    ├── 02_http_whoami_www_data.png
    ├── 03_tcp_callback_ncat.png
    ├── 04_reverse_shell_session.png
    └── 05_root_access_and_su_failure_redacted.png

No exploit source, payload source, raw PCAP, raw Docker evidence package, or DOCX source files are included.

Test environment

RoleSystem
Victim hostUbuntu 24.04.4 LTS, kernel 6.17.0-35-generic, Docker Engine 29.5.3
Target applicationJoomla 5.4.7, PHP 8.3.32, Apache HTTP Server, image joomla:5-php8.3-apache
ComponentJoomShaper SP Page Builder
Containerjoomla5-builders
Attacker workstationMicrosoft Windows 11 Home 10.0.26200
Joomla servicehttp://172.20.10.3:8080
Windows test address172.20.10.2
Container address172.21.0.3
Test date9 July 2026

The Joomla webroot /var/www/html was backed by the Docker volume joomla5-builders_joomla_data. This matters for detection: docker diff did not provide detailed visibility into file changes inside the volume, so file monitoring had to rely on volume-aware file listings and host-side monitoring guidance.

What was validated

The test was performed in an isolated and authorized laboratory environment. The validation covered the following sequence:

  1. Joomla 5 was deployed in Docker with SP Page Builder installed.
  2. A public project listed in References was used as the initial validation reference.
  3. The SP Page Builder asset.uploadCustomIcon endpoint accepted uploaded icon archives in the laboratory environment.
  4. New directories and files were created under /media/com_sppagebuilder/assets/iconfont/.
  5. The uploaded content included mixed-case PHP extensions and an .htaccess file that changed PHP handling for the .PHP extension.
  6. The uploaded PHP artifact was invoked over HTTP and executed controlled commands.
  7. A one-time TCP callback to the Windows host confirmed outbound connectivity.
  8. A controlled reverse shell test confirmed interactive command execution as the web server user.
  9. Attempts to access /root and to switch user with su - failed.
  10. Evidence from victim-side telemetry and Windows screenshots was correlated into a single UTC timeline.

The reports intentionally document evidence and detection logic without distributing a reusable exploit or payload implementation.

Confirmed result

The laboratory test confirmed:

  • unauthorized upload through the SP Page Builder asset.uploadCustomIcon endpoint;
  • creation of PHP and .htaccess artifacts under the Joomla media directory;
  • server-side execution of the uploaded PHP artifact after an HTTP request;
  • execution in the context of the Apache/PHP process user;
  • outbound TCP connectivity from the Joomla container to the Windows host;
  • an interactive reverse shell session as www-data;
  • no confirmed privilege escalation to root.

Inside the container, the effective identity was:

uid=33(www-data) gid=33(www-data) groups=33(www-data)

The failed privilege-escalation attempt was visible as:

cd root
bash: cd: root: Permission denied
su -
Password:
su: Authentication failure

Key evidence

Public PoC validation and upload behavior

The public PoC tested several extension variants and confirmed that a combination involving a mixed-case PHP extension and .htaccess could lead to execution in the laboratory setup.

PoC upload and code execution

Code execution as the web server user

A controlled HTTP request executed whoami, and the browser displayed the effective process user.

HTTP whoami result

One-time TCP callback

Before the interactive test, a safer single-message callback was used to confirm outbound connectivity from the target environment to the Windows host on TCP port 4444.

One-time TCP callback

Reverse shell session

The interactive session confirmed execution as www-data, Linux as the operating system, and a working directory under the Joomla SP Page Builder media path.

Reverse shell session

Failed root access attempt

Attempts to access /root and authenticate with su - failed. The screenshot is redacted to avoid publishing the test password.

Failed root access and su attempt

Reconstructed timeline

The complete timeline is available in both PDF reports. The most important events were:

Download Tool