CVE-2026-65879: Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1
Published Jul 27, 2026
·Updated
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
Affected Software
1 affected component
Joomla Extension - SP Page Builder<6.7.1
Event History
Jul 27, 2026
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65879?
CVE-2026-65879 has a critical severity rating of 9.8 according to CVSS 3.1.
2
How do I fix CVE-2026-65879?
To fix CVE-2026-65879, upgrade your SP Page Builder to version 6.7.1 or later.
3
What exploitation risks are associated with CVE-2026-65879?
CVE-2026-65879 allows unauthenticated attackers to perform mail relay attacks using a hardcoded secret.
4
Which versions of SP Page Builder are affected by CVE-2026-65879?
CVE-2026-65879 affects all versions of SP Page Builder prior to 6.7.1.
5
What impact does CVE-2026-65879 have on Joomla user security?
CVE-2026-65879 compromises user security by enabling attackers to forge the 'from' address of emails sent from Joomla forms.