CVE-2026-56290

CRITICAL KEV NUCLEI

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-56290 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 7, 2026. EIP tracks 6 public exploits from researchers including M@rAz Ali, ChiefYoru, HORKimhab. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets an unauthenticated arbitrary file upload vulnerability in Joomla Page Builder CK (versions <= 3.5.10) via the 'fonts.save' task. It bypasses CSRF protection by extracting a publicly readable token from the homepage and uploads a malicious PHP file to achieve remote code execution.

Description

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Exploits (6)

exploitdb WORKING POC
by M@rAz Ali · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52626

This exploit targets an unauthenticated arbitrary file upload vulnerability in Joomla Page Builder CK (versions <= 3.5.10) via the 'fonts.save' task. It bypasses CSRF protection by extracting a publicly readable token from the homepage and uploads a malicious PHP file to achieve remote code execution.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla Page Builder CK <= 3.5.10 (com_pagebuilderck)
No auth needed
Prerequisites: Target must have Joomla Page Builder CK <= 3.5.10 installed · Attacker must host a malicious callback URL serving crafted font.css and payload · Target must have PHP execution enabled in the webroot
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →
github WORKING POC
by ChiefYoru · pythonpoc
https://github.com/ChiefYoru/CVE-2026-56290_PoC

This exploit targets CVE-2026-56290, a pre-authentication arbitrary file upload vulnerability in Page Builder CK (com_pagebuilderck) for Joomla, leading to remote code execution. The PoC automates endpoint discovery, CSRF token harvesting, and webshell deployment with WAF bypass techniques via extension variation.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Page Builder CK (com_pagebuilderck) Joomla extension versions <= 3.5.10
No auth needed
Prerequisites: Target must have Page Builder CK Joomla extension installed · Vulnerable version (<= 3.5.10) of the extension · Writable media/com_pagebuilderck/ or similar directory
mistral-large-3 · analyzed Jul 19, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/56xxx/CVE-2026-56290.md

The repository contains no actual exploit code or technical details about the vulnerability. It only lists external links to other GitHub repositories and an encrypted backup file hosted on an archive service, which is a common social engineering tactic.

Classification
Suspicious 98%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Joomla Extension - Page Builder CK < 3.6.0
No auth needed
Prerequisites: Access to a vulnerable Joomla instance with Page Builder CK extension installed
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
github WORKING POC
by Jenderal92 · pythonremote
https://github.com/Jenderal92/CVE-2026-56290

This PoC exploits an unrestricted file upload vulnerability (CVE-2026-56290) in the Joomla component com_pagebuilderck, allowing remote attackers to upload arbitrary PHP files and achieve remote code execution (RCE). The exploit includes token extraction, file upload, and shell verification mechanisms.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla! CMS with com_pagebuilderck component
No auth needed
Prerequisites: Target must have com_pagebuilderck installed and accessible · PHP file upload must not be blocked by server/WAF · Target must be running a vulnerable version of the component
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
github TROJAN
by sagsooz · pythonpoc
https://github.com/sagsooz/PageBuilderCK-CVE-2026-56290-Exploit

The repository claims to be a PoC for CVE-2026-56290 (Joomla Page Builder CK RCE) but contains heavily obfuscated exploit code with integrity checks and a hidden payload. The exploit.py file decompresses and executes obfuscated code at runtime, a hallmark of malicious trojanized PoCs. The scanner.py is legitimate but the exploit is deceptive.

Classification
Trojan 99%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla Page Builder CK (com_pagebuilderck) component
No auth needed
Prerequisites: Vulnerable Joomla installation with Page Builder CK component · Network access to target
mistral-large-3 · analyzed Jul 04, 2026 Full analysis →
github WORKING POC
by shinthink · pythonremote
https://github.com/shinthink/pbck-exploit

This exploit targets CVE-2026-56290, an unauthenticated arbitrary file upload vulnerability in Page Builder CK for Joomla, leading to remote code execution (RCE). The PoC includes mass exploitation capabilities, endpoint discovery, and validated backdoor paths with live output logging.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Page Builder CK for Joomla (versions vulnerable to CVE-2026-56290)
No auth needed
Prerequisites: Target must have Page Builder CK installed and accessible · Web server must have write permissions to predictable paths (e.g., media/com_pagebuilderck/) · PHP execution must not be blocked by WAF or .htaccess rules
mistral-large-3 · analyzed Jul 04, 2026 Full analysis →

Nuclei Templates (1)

Page Builder CK <= 3.5.10 - Unauthenticated Arbitrary File Upload
CRITICALVERIFIEDby panchiko-p,0x_Akoko
Shodan: http.html:"com_pagebuilderck"
FOFA: body="com_pagebuilderck"

Scores

CVSS v3 9.8
EPSS 0.8325
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-07
VulnCheck KEV 2026-06-27
ENISA EUVD EUVD-2026-40121
CWE
CWE-434
Status published
Products (2)
joomlack/page_builder_ck < 3.6.0
joomlack.fr/JoomlaCK.fr Page Builder CK extension for Joomla 1.0-3.6.0
Published Jun 29, 2026
KEV Added Jul 07, 2026
Tracked Since Jun 29, 2026