CRITICAL
CVE-2026-56290
CVSS
9.8
KEV
Description
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Summary dbcve.org
Unauthenticated arbitrary file upload vulnerability in Page Builder CK Joomla extension (versions < 3.6.0) allowing attackers to upload executable files directly to the web server, leading to complete remote code execution.
Mitigation
Upgrade Page Builder CK extension to version 3.6.0 or later. If immediate upgrade is not feasible, disable the extension or implement web server-level access controls to block unauthorized upload endpoints.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
30.87%
Probability of exploitation in next 30 days
98.2th percentile
References
https://www.joomlack.fr/
Product
https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3
Issue Tracking, Patch
https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.