Junglewise Threat Intelligence

CVE-2026-56290: Joomlack Page Builder CK unauthenticated arbitrary file upload

CVE-2026-56290 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-06-29

Executive brief

Joomlack Page Builder CK, a popular tool for designing Joomla websites, contains a critical security flaw that allows unauthorized users to upload files to the server. An attacker can use this to upload malicious scripts and take complete control of the website. This could lead to the theft of customer data, website defacement, or the site being used to host further malware.

Technical details

The Page Builder CK extension for Joomla (versions 1.0 through 3.6.0) is vulnerable to an unauthenticated arbitrary file upload (CWE-434). Due to improper access controls, a remote attacker can upload executable files (such as PHP scripts) to the web server without requiring any authentication or user interaction. Once uploaded, these files can be executed to achieve full remote code execution (RCE) with the privileges of the web server process. A patch has been released by the vendor to address this issue.

Affected products

  • Joomlack.fr Page Builder CK extension for Joomla 1.0 through 3.6.0

Timeline

  • 2026-06-29: disclosed: Initial CVE record received from Joomla! Project
  • 2026-07-02: advisory: NIST initial analysis and CVSS scoring completed
  • 2026-07-05: patched: Vendor patch information updated in CVE record
  • 2026-07-07: advisory: NVD publication date

Related threats