Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-56290

Published 2026-06-29
Updated 2 months ago
Vendor/s
Joomlack
Product/s
Page Builder
Version/s
* > 3.6.0
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-56290 is a critical RCE vulnerability in Joomlack Page Builder CK < 3.6.0. Actively exploited and listed on CISA KEV. Update immediately.

CPE

Joomlack logo
Joomlack
Product Version Start Version End (excl.) Status
page_builder_ck * 3.6.0 vulnerable

Related weakness (CWE)

CWE-434, CWE-434

Remediation plan

1

Apply official patches

Download and install the latest security update from Joomlack for the Page Builder CK extension to close the unauthenticated file upload vulnerability.

2

Update affected systems

Ensure all Joomla installations running Page Builder CK versions prior to 3.6.0 are upgraded to version 3.6.0 or later immediately to mitigate RCE risks.

3

Restrict access

Limit access to the Joomla administrative backend and audit file upload permissions for the Page Builder component to reduce the attack surface for unauthenticated users.

4

Monitor for exploitation

Review web server logs for unusual POST requests to the Page Builder CK directory and check for unauthorized PHP files in the extension's upload folders.

Detection Guidance

"Monitor web server access logs for suspicious POST requests targeting the Page Builder CK component, particularly those originating from unknown IP addresses. Use file integrity monitoring (FIM) to detect newly created or modified PHP files within the extension's directories. Additionally, inspect network traffic for outbound connections from the web server that may indicate a reverse shell or communication with a command-and-control server following a successful file upload."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management