Unauthenticated Arbitrary File Upload Vulnerability in Joomla Extension Page Builder CK
CVE-2026-56290

10CRITICAL

Key Information:

Vendor
CVE Published:
29 June 2026

Badges

📈 Score: 127👾 Exploit Exists🟡 Public PoC🦅 CISA Reported

What is CVE-2026-56290?

CVE-2026-56290 is a severe security vulnerability found in the Page Builder CK extension for Joomla, a popular content management system (CMS) used for website development. This vulnerability allows unauthenticated users to upload arbitrary files, including potentially malicious executable files, without proper authentication. The exploit leads to remote code execution (RCE), which means that attackers could take complete control of a server running the affected extension. Since the Page Builder CK extension is widely utilized for constructing and managing websites, the presence of this vulnerability poses a significant risk to organizations, potentially exposing sensitive data and systems to unauthorized access, manipulation, and attacks.

Potential impact of CVE-2026-56290

  1. Remote Code Execution: The most critical impact of this vulnerability is the ability for attackers to execute arbitrary code on the server. This could lead to full control over the affected system, allowing cybercriminals to install malware, exfiltrate sensitive information, or manipulate website content.

  2. Data Breaches: Exploitation of this vulnerability could result in unauthorized access to sensitive data stored on the web server, leading to data breaches. Organizations may face severe repercussions, including legal penalties, loss of reputation, and financial damage due to compromised customer information.

  3. Increased Vulnerability to Further Attacks: Once attackers gain access through this vulnerability, they may exploit further vulnerabilities within the system or extend their attack to connected networks. This could facilitate a broader attack surface, potentially impacting multiple systems and services within an organization's infrastructure.

CISA has reported CVE-2026-56290

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-56290 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

JoomlaCK.fr Page Builder CK extension for Joomla 1.0-3.6.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🦅

    CISA Reported

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.