# CVE-2026-56290: JoomlaCK.fr Page Builder For Joomla - Arbitrary File Upload

> Live exploitation tracking for CVE-2026-56290 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-56290

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 10.0
- **Public exploit available:** Yes
- **Affected products:** JoomlaCK.fr Page Builder CK Extension For Joomla
- **Weaknesses:** CWE-434 (Unrestricted Upload of File with Dangerous Type)
- **Tags:** cms, web_application

## Description

Joomla Extension JoomlaCK.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

## CrowdSec analysis

[CVE-2026-56290](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-56290) is a critical unauthenticated arbitrary file upload vulnerability in the JoomlaCK.fr Page Builder CK Extension For Joomla versions below 3.6.0. Remote attackers can upload executable files without authentication, potentially achieving full remote code execution and compromising the Joomla website and underlying server.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-56290 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target Joomla’s Page Builder CK upload handler at `/index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture`, using an unauthenticated multipart file upload to place files under `media/com_pagebuilderck/gfonts/`. Follow-up requests to `/media/com_pagebuilderck/gfonts/<filename>` verify the uploaded content and may enable executable-file deployment and remote code execution.

## Timeline

- 2026-06-29: CVE Published. CVE-2026-56290 is published to NVD.
- 2026-07-07: CISA KEV. CVE-2026-56290 is added to the Known Exploited Vulnerabilities catalog by CISA.
- 2026-07-10: CISA Remediation Deadline. Expiration of the CISA remediation deadline as described in [BOD 22-01](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities).
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2026-56290 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-56290 for the first time.

## References

- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290
- https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-56290.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-56290) follows observed exploitation activity for CVE-2026-56290. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
