CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-07. EPSS: 30.9% chance of exploitation in the next 30 days.
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Affected products
- Joomlack Page Builder Ck: before 3.6.0 (fixed in 3.6.0)
Published 2026-06-29. Last modified 2026-10-07.