CVE-2026-56290 is a critical RCE vulnerability in Joomlack Page Builder CK < 3.6.0. Actively exploited and listed on CISA KEV. Update immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| page_builder_ck | * | 3.6.0 | vulnerable |
Download and install the latest security update from Joomlack for the Page Builder CK extension to close the unauthenticated file upload vulnerability.
Ensure all Joomla installations running Page Builder CK versions prior to 3.6.0 are upgraded to version 3.6.0 or later immediately to mitigate RCE risks.
Limit access to the Joomla administrative backend and audit file upload permissions for the Page Builder component to reduce the attack surface for unauthenticated users.
Review web server logs for unusual POST requests to the Page Builder CK directory and check for unauthorized PHP files in the extension's upload folders.
"Monitor web server access logs for suspicious POST requests targeting the Page Builder CK component, particularly those originating from unknown IP addresses. Use file integrity monitoring (FIM) to detect newly created or modified PHP files within the extension's directories. Additionally, inspect network traffic for outbound connections from the web server that may indicate a reverse shell or communication with a command-and-control server following a successful file upload."
Experience superior visibility and a simpler approach to cyber risk management