Junglewise Threat Intelligence

CVE-2026-81566: JoomShaper SP Page Builder missing access control in menu item creation

CVE-2026-81566 · Severity: info · Published 2026-09-14

Technologies: JoomShaper SP Page Builder. Vendors: JoomShaper.

Executive brief

SP Page Builder is a popular drag-and-drop page composer extension for Joomla CMS. The extension fails to properly check user permissions when creating or modifying Joomla menu items, allowing unprivileged users—even those with no menu management rights—to create new menu items or overwrite existing ones, potentially including the site's home page link.

Technical details

The vulnerability is a missing access control (authorization bypass) in the add-to-menu routine of SP Page Builder. The code directly invokes the com_menus component's save() method without performing authorization checks; it relies only on a core.edit permission check against com_sppagebuilder itself, not com_menus. Since the actual authorization logic for menu operations resides in the com_menus controller, this direct model invocation circumvents those checks. An attacker with SP Page Builder access but no com_menus permissions can craft menu item creation requests, including overwriting existing menu items by controlling the jform[menuid] field. The site's home page flag is read back from the database and preserved, allowing attackers to repoint the site's home menu item while keeping it designated as the home page.

Affected products

  • JoomShaper SP Page Builder 4.0.0 to 6.9.0

Timeline

  • 2026-09-14: disclosed

References

Related threats