CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-56290Public Exploit

JoomlaCK.fr Page Builder For Joomla - Arbitrary File Upload (CVE-2026-56290)

PublishedJun 29, 2026
First SeenAug 19, 2026
Last Seen
Reported
CVSS10.0
cmsweb_application

Description

Joomla Extension JoomlaCK.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

psychologyCrowdSec Analysis

CVE-2026-56290 is a critical unauthenticated arbitrary file upload vulnerability in the JoomlaCK.fr Page Builder CK Extension For Joomla versions below 3.6.0. Remote attackers can upload executable files without authentication, potentially achieving full remote code execution and compromising the Joomla website and underlying server.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-56290 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target Joomla’s Page Builder CK upload handler at /index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture, using an unauthenticated multipart file upload to place files under media/com_pagebuilderck/gfonts/. Follow-up requests to /media/com_pagebuilderck/gfonts/<filename> verify the uploaded content and may enable executable-file deployment and remote code execution.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-06-29
CISA KEV2026-07-07
CISA Remediation Deadline2026-07-10
Rule Released2026-08-03
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.