CVE-2026-62414

joomlack.fr · Page Builder CK extension for Joomla

The Page Builder CK extension for Joomla contains an improper access control vulnerability that permits unauthenticated users to view or interact with restricted frontend page list data.

Executive summary

An improper access control vulnerability in the Page Builder CK extension for Joomla permits unauthorized information disclosure by unauthenticated remote attackers.

Vulnerability

This is an improper access control (CWE-284) vulnerability where the extension fails to enforce security checks on frontend page list views. An unauthenticated remote attacker can exploit this flaw to bypass intended restrictions and access sensitive information.

Business impact

The exploitation of this vulnerability can lead to the unauthorized exposure of site content and administrative structures, potentially revealing private or sensitive page data. With a CVSS score of 9.1, this flaw is categorized as critical because it allows unauthenticated access to potentially confidential information. Such data exposure can lead to reputational damage and facilitate further targeted attacks against the Joomla environment.

Remediation

Immediate Action: Update the Page Builder CK extension to version 3.6.2 or later immediately.

Proactive Monitoring: Review web server access logs for anomalous requests directed at frontend page list views or unexpected data access patterns.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized access to the specific paths associated with Page Builder CK frontend listings.

Exploitation status

Public Exploit Available: No confirmed public exploit available.

Analyst recommendation

Given the critical severity of this access control vulnerability, site administrators should treat the update to version 3.6.2 as a high-priority task. Ensuring that all extensions are kept up-to-date is vital for maintaining the security posture of the Joomla installation and protecting sensitive site data.