Junglewise Threat Intelligence

CVE-2026-62414: Joomlack Page Builder CK improper access control in page list views

CVE-2026-62414 · Severity: info · CVSS 5.3 · Published 2026-07-20

Executive brief

Page Builder CK is a popular drag-and-drop page creation tool for the Joomla content management system. A security flaw in this extension allows unauthorized users to view lists of pages on the website that should be restricted. This could lead to the exposure of private page titles or site structure information to the general public.

Technical details

An improper access control vulnerability (CWE-284) exists in the Page Builder CK extension for Joomla, specifically within the frontend page list views. The application fails to validate user permissions before displaying these lists, allowing unauthenticated or unauthorized network-based attackers to view page indexes that should be restricted. This issue affects versions 1.0.0 through 3.6.1. Attackers can exploit this to map out site architecture or discover hidden page titles without valid credentials.

Affected products

  • Joomlack.fr Page Builder CK extension for Joomla 1.0.0-3.6.1

Timeline

  • 2026-07-20: disclosed: CVE-2026-62414 published by the Joomla! Project.

References

Related threats