CVE-2026-56290: Joomlack Page Builder Improper Access Control Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-07. EPSS: 30.9% chance of exploitation in the next 30 days.

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Affected products

  • Joomlack Page Builder Ck: before 3.6.0 (fixed in 3.6.0)

Published 2026-06-29. Last modified 2026-10-07.