JoomlaCK Page Builder CK Extension RCE via Unauth File Upload (v1.0-3.6.0)
CVE-2026-56290 Published on June 29, 2026

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

NVD

Known Exploited Vulnerability

This Joomlack Page Builder Improper Access Control Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

The following remediation steps are recommended / required by July 10, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab

Vulnerability Analysis

CVE-2026-56290 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors in an automatable fashion. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

What is an Unrestricted File Upload Vulnerability?

The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

CVE-2026-56290 has been classified to as an Unrestricted File Upload vulnerability or weakness.


Affected Versions

JoomlaCK.fr Page Builder CK extension for Joomla Version 1.0-3.6.0 is affected by CVE-2026-56290