Description
Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the relevant checks reside in the com_menus controller, and the only check applied was core.edit on com_sppagebuilder. Users with no permissions whatsoever on com_menus could therefore create menu items, and because the record identifier was taken from the submitted jform[menuid] field, could also overwrite existing ones. The home flag was read back from the database and preserved, so the site's home menu item could be repointed while remaining the home item.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of site navigation items potentially affecting site structure and home page redirection
Action: Apply update promptly
AI Analysis

Impact

The vulnerability arises from a missing access‑control check in the SP Page Builder extension’s menu‑item creation routine. The routine calls the Joomla core com_menus model’s save() method directly, but the model itself does not perform any authorization; the necessary checks exist result, any authenticated Joomla user – even one with no permissions on com_menus – can create new menu items or overwrite existing ones by submitting a jform[menuid] value. An attacker can therefore redirect the site, undermining the integrity and availability of the website’s menu structure.

Affected Systems

Vulnerable to all installations of the joomshaper.com SP Page Builder extension for Joomla, both the free and pro editions, with affected versions ranging from 4.0.0 through 6.9.0. Any site running one of those releases is susceptible.

Risk and Exploitability

The CVSS score of 5.1 classifies the flaw as moderate, reflecting that the exploitation requires authenticated access but does not provide direct code execution or disclose data. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers with a Joomla account, even with minimal privileges, can exploit this weakness by invoking the add‑to‑menu feature and supplying a target menu ID, thereby creating or overwriting site’s navigation and link structure, but this can be leveraged to hide malicious content or redirect users.

Generated by OpenCVE AI on September 15, 2026 at 14:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the SP Page Builder extension to a version newer than 6.9.0 once an official patch is released.
  • Use Joomla’s ACL to remove com_menus write permissions for all user groups except administrators, thereby preventing unauthorized menu edits.
  • Disable or remove the add‑to‑menu feature from the extension if not needed, and monitor system logs for unexpected menu creation or overwrite actions.

Generated by OpenCVE AI on September 15, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the relevant checks reside in the com_menus controller, and the only check applied was core.edit on com_sppagebuilder. Users with no permissions whatsoever on com_menus could therefore create menu items, and because the record identifier was taken from the submitted jform[menuid] field, could also overwrite existing ones. The home flag was read back from the database and preserved, so the site's home menu item could be repointed while remaining the home item.
Title Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:47:02.406Z

Reserved: 2026-08-27T06:42:00.961Z

Link: CVE-2026-81566

cve-icon Vulnrichment

Updated: 2026-09-14T14:29:52.288Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:04.993

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-81566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses