Threat intel / CVE tracker
CVE-2026-56290
Critical KEV · actively exploited PoC availableCVSS base score
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HJoomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Vendor
joomlack
Product
page builder ck
Affected
joomlack page builder ck
Weakness
CWE-434 · File upload
Published
Jun 29, 2026
Last modified
Jul 24, 2026
CVSS version
v3.1
Views
8
// References & exploits
https://www.joomlack.fr/Producthttps://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3Issue TrackingPatchhttps://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/PoCThird Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290US Government Resource