CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Other sources
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56290?
CVE-2026-56290 has a critical severity rating of 10.
How do I fix CVE-2026-56290?
To fix CVE-2026-56290, upgrade the Page Builder CK extension to version 3.6.0 or later.
What risks does CVE-2026-56290 pose to my Joomla installation?
CVE-2026-56290 allows unauthenticated arbitrary file uploads, potentially leading to full remote code execution.
Is CVE-2026-56290 specific to certain versions of Page Builder CK?
Yes, CVE-2026-56290 affects Page Builder CK versions prior to 3.6.0.
What type of attack can be executed using CVE-2026-56290?
CVE-2026-56290 can be exploited to upload executable files, leading to remote code execution on the server.