Serious Impact From CVE-2026-48908 (SP Page Builder RCE) — Request For Improved Security Communication - Question | JoomShaper

Serious Impact From CVE-2026-48908 (SP Page Builder RCE) — Request For Improved Security Communication

Osho Nisarga Foundation

Osho Nisarga Foundation

SP Page Builder 1 week ago

Dear JoomShaper team,

I am a long-standing SP Page Builder customer running several Joomla websites for a meditation centre and a small adventure-travel business in the Himalayas. I am writing to make you aware of the serious, real-world impact that the critical vulnerability CVE-2026-48908 (the unauthenticated arbitrary file upload / RCE via asset.uploadCustomIcon) had on my websites, and to ask you to improve how you communicate critical security issues to your customers.

Through this vulnerability, attackers uploaded multiple PHP web shells into the SP Page Builder icon directories across more than one of my sites. Using that access they:

defaced my main site (os------ga.com), injected hidden casino/betting spam links into pages, and — most damagingly — used the foothold to submit Google Search Console removal requests that hid my entire website from Google for roughly three weeks.

The result was a near-total loss of search traffic and enquiries during that period, significant financial and reputational harm to a charitable organisation, and close to three weeks of intensive, stressful recovery work. This was a CVSS 10.0 vulnerability in your flagship product, exploitable by anyone with no authentication whatsoever — the most severe class of flaw a web application can have.

I acknowledge that you released a fix in version 6.6.2. My concern is this: I received no proactive notification from you that a critical, actively-exploited vulnerability had been patched and that I needed to update urgently. I only learned the root cause after my hosting provider's forensic analysis, well after the damage was done. For a vulnerability that CISA added to its Known Exploited Vulnerabilities catalogue, silent publication of a patch is not enough — by the time customers discover it on their own, they have often already been breached, as I was. I would therefore urge you to:

Proactively email all license holders immediately whenever a critical (high/critical severity) security fix is released, with a clear "update now" instruction — not rely on customers noticing a version bump. Consider an in-dashboard security alert for critical updates, distinct from routine feature updates. Acknowledge the impact this incident has had on affected customers.

I still value SP Page Builder and intend to keep using it — which is precisely why I am taking the time to write constructively rather than simply leaving. I would appreciate a response acknowledging these points and outlining what you will do to notify customers of critical vulnerabilities in future.

Yours sincerely,

Rahi

0
2 Answers
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 1 week ago #229257

Hello Osho Nisarga Foundation,

Thank you very much for taking the time to share your experience.

First of all, we are truly sorry to hear about the impact this incident had on your websites, your organization, and the considerable time and effort you had to invest in the recovery process. We understand how distressing it must have been to deal with website defacement, spam injection, and the loss of search visibility, and we sincerely appreciate you sharing these details with us.

I appreciate your constructive feedback regarding our communication of critical security updates. Your suggestions about proactive email notifications, dedicated in-dashboard security alerts, and clearer communication for high-severity vulnerabilities have been noted. We have immediately fixed the issues as soon as we get it. Then we have sent newsletters to the users to update SP Page Builder version. I think it is not possible to add in-dashboard security alert. However, I have shared your feedback with our product and management teams for review as we continue to improve both our security practices and customer communications.

We are grateful that, despite this experience, you continue to place your trust in SP Page Builder and have taken the time to provide thoughtful recommendations rather than simply moving on. Feedback like yours helps us identify areas where we can improve.

Best regards

0
J
jcalvert
Accepted Answer
1 week ago #229291

I agree. I spent a lot of time dealing with the hacks caused by these vulnerabilities. Even today I was not aware that there was another update, to Helix Ultimate, and so one of my client sites was hacked and this is a very mission critical website. The site was offline today for about 4 hours while I worked through the situation.

I am suggesting that JoomShaper set up a special email list for customers so that critical security updates can come quickly through that channel.

My friends, I think we are witnessing that hackers are now using AI.

0