CVE-2026-65879: Vulnerability in joomshaper.com SP Page Builder extension for Joomla
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
AI Analysis
Technical Summary
CVE-2026-65879 is a critical security vulnerability in the SP Page Builder extension for Joomla (versions 1.0.0 to 6.7.0) caused by a hardcoded, product-wide secret. This secret enables unauthenticated attackers to perform mail relay attacks by forging the 'from' address in form submissions. The vulnerability impacts confidentiality, integrity, and availability, as reflected by its CVSS 3.1 score of 9.8. No official patch or remediation level has been disclosed by the vendor at the time of this report.
Potential Impact
Exploitation of this vulnerability allows unauthenticated attackers to send emails with forged 'from' addresses via the vulnerable Joomla extension. This can facilitate phishing, spam, or other malicious email activities, potentially damaging the reputation of affected domains and compromising trust. The CVSS score indicates high impact on confidentiality, integrity, and availability, but no known exploits are reported in the wild yet.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling the affected extension or restricting access to forms that could be abused for mail relay. Monitor vendor communications for updates on patches or official mitigations.
CVE-2026-65879: Vulnerability in joomshaper.com SP Page Builder extension for Joomla
Description
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65879 is a critical security vulnerability in the SP Page Builder extension for Joomla (versions 1.0.0 to 6.7.0) caused by a hardcoded, product-wide secret. This secret enables unauthenticated attackers to perform mail relay attacks by forging the 'from' address in form submissions. The vulnerability impacts confidentiality, integrity, and availability, as reflected by its CVSS 3.1 score of 9.8. No official patch or remediation level has been disclosed by the vendor at the time of this report.
Potential Impact
Exploitation of this vulnerability allows unauthenticated attackers to send emails with forged 'from' addresses via the vulnerable Joomla extension. This can facilitate phishing, spam, or other malicious email activities, potentially damaging the reputation of affected domains and compromising trust. The CVSS score indicates high impact on confidentiality, integrity, and availability, but no known exploits are reported in the wild yet.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider disabling the affected extension or restricting access to forms that could be abused for mail relay. Monitor vendor communications for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-07-23T09:17:01.409Z
- State
- PUBLISHED
Threat ID: 6a675f279c2644c7f820eba7
Added to database: 07/27/2026, 13:37:43 UTC
Last enriched: 08/13/2026, 13:45:51 UTC
Last updated: 09/10/2026, 18:10:38 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.