CVE-2026-62414
Received Received - Intake

Improper Access Control in Page Builder CK Joomla Extension

Vulnerability report for CVE-2026-62414, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: Joomla! Project

Description

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joomla page_builder_ck *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Joomla extension Page Builder CK fails to enforce proper access controls on frontend page list views. This means unauthorized users may be able to view or interact with restricted page listings.

Detection Guidance

To detect this vulnerability, check if the Page Builder CK Joomla extension is installed and verify if frontend page list views are accessible without proper access control. Inspect server logs for unauthorized access attempts to page listings. No specific commands are provided in the context.

Impact Analysis

If you use Page Builder CK on your Joomla site, attackers could access sensitive page information without authentication. This may lead to data exposure or unauthorized modifications depending on the site's configuration.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls for sensitive data, such as GDPR's data protection principles or HIPAA's safeguards for protected health information.

Mitigation Strategies

Update the Page Builder CK extension to the latest version as soon as possible. Remove or restrict access to frontend page list views if not required. Review user permissions to ensure proper access control is enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62414. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart