CVE-2026-67286: Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0
Published Aug 12, 2026
·Updated
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.
Affected Software
1 affected component
SP Page Builder<6.8.0
Event History
Aug 12, 2026
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67286?
CVE-2026-67286 has a risk rating of 70, indicating a significant security vulnerability.
2
What is CVE-2026-67286?
CVE-2026-67286 is a vulnerability in the SP Page Builder that allows unauthenticated attackers to create arbitrary directories and files.
3
How do I fix CVE-2026-67286?
To fix CVE-2026-67286, update your SP Page Builder to version 6.8.0 or later.
4
Who is affected by CVE-2026-67286?
The vulnerability affects users of SP Page Builder versions prior to 6.8.0.
5
What is the impact of CVE-2026-67286?
The impact of CVE-2026-67286 includes unauthorized directory creation and file writing, leading to potential data compromise.