Executive brief
Page Builder CK is a popular drag-and-drop page creation tool for the Joomla content management system. A security flaw in this extension allows unauthorized users to view lists of pages on the website that should be restricted. This could lead to the exposure of private page titles or site structure information to the general public.
Technical details
An improper access control vulnerability (CWE-284) exists in the Page Builder CK extension for Joomla, specifically within the frontend page list views. The application fails to validate user permissions before displaying these lists, allowing unauthenticated or unauthorized network-based attackers to view page indexes that should be restricted. This issue affects versions 1.0.0 through 3.6.1. Attackers can exploit this to map out site architecture or discover hidden page titles without valid credentials.
Affected products
- Joomlack.fr Page Builder CK extension for Joomla 1.0.0-3.6.1
Timeline
- 2026-07-20: disclosed: CVE-2026-62414 published by the Joomla! Project.