CVE-2026-56290
CRITICAL KEV NUCLEIJoomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
Title source: cnaExploitation Summary
CVE-2026-56290 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 7, 2026. EIP tracks 6 public exploits from researchers including M@rAz Ali, ChiefYoru, HORKimhab. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit targets an unauthenticated arbitrary file upload vulnerability in Joomla Page Builder CK (versions <= 3.5.10) via the 'fonts.save' task. It bypasses CSRF protection by extracting a publicly readable token from the homepage and uploads a malicious PHP file to achieve remote code execution.
Description
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Exploits (6)
This exploit targets an unauthenticated arbitrary file upload vulnerability in Joomla Page Builder CK (versions <= 3.5.10) via the 'fonts.save' task. It bypasses CSRF protection by extracting a publicly readable token from the homepage and uploads a malicious PHP file to achieve remote code execution.
This exploit targets CVE-2026-56290, a pre-authentication arbitrary file upload vulnerability in Page Builder CK (com_pagebuilderck) for Joomla, leading to remote code execution. The PoC automates endpoint discovery, CSRF token harvesting, and webshell deployment with WAF bypass techniques via extension variation.
The repository contains no actual exploit code or technical details about the vulnerability. It only lists external links to other GitHub repositories and an encrypted backup file hosted on an archive service, which is a common social engineering tactic.
This PoC exploits an unrestricted file upload vulnerability (CVE-2026-56290) in the Joomla component com_pagebuilderck, allowing remote attackers to upload arbitrary PHP files and achieve remote code execution (RCE). The exploit includes token extraction, file upload, and shell verification mechanisms.
The repository claims to be a PoC for CVE-2026-56290 (Joomla Page Builder CK RCE) but contains heavily obfuscated exploit code with integrity checks and a hidden payload. The exploit.py file decompresses and executes obfuscated code at runtime, a hallmark of malicious trojanized PoCs. The scanner.py is legitimate but the exploit is deceptive.
This exploit targets CVE-2026-56290, an unauthenticated arbitrary file upload vulnerability in Page Builder CK for Joomla, leading to remote code execution (RCE). The PoC includes mass exploitation capabilities, endpoint discovery, and validated backdoor paths with live output logging.
Nuclei Templates (1)
http.html:"com_pagebuilderck"
body="com_pagebuilderck"
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H