JoomlaCK.fr Page Builder For Joomla - Arbitrary File Upload (CVE-2026-56290)
Description
Joomla Extension JoomlaCK.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
psychologyCrowdSec Analysis
CVE-2026-56290 is a critical unauthenticated arbitrary file upload vulnerability in the JoomlaCK.fr Page Builder CK Extension For Joomla versions below 3.6.0. Remote attackers can upload executable files without authentication, potentially achieving full remote code execution and compromising the Joomla website and underlying server.
CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-56290 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers target Joomla’s Page Builder CK upload handler at /index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture, using an unauthenticated multipart file upload to place files under media/com_pagebuilderck/gfonts/. Follow-up requests to /media/com_pagebuilderck/gfonts/<filename> verify the uploaded content and may enable executable-file deployment and remote code execution.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-06-29 |
| CISA KEV | 2026-07-07 |
| CISA Remediation Deadline | 2026-07-10 |
| Rule Released | 2026-08-03 |
| CrowdSec First Seen | 2026-08-19 |