CVE-2026-56290 Scanner

CVE-2026-56290 Scanner - Unauthenticated Arbitrary File Upload vulnerability in Page Builder CK

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

13 days 5 hours

Scan only one

Domain, Subdomain, IPv4

Toolbox

Page Builder CK is a popular Joomla extension used by website developers to create and manage pages more efficiently. It is particularly common among individuals and businesses needing simple or advanced page layouts without extensive coding. With its drag-and-drop functionality, Page Builder CK enhances Joomla's flexibility and usability, allowing users to design unique web pages with ease. Organizations commonly rely on it to ensure their websites maintain professional aesthetics and functionality. Created by Joomlack, it has gained considerable adoption due to its user-friendly interface and customizable templates. However, keeping such extensions secure from vulnerabilities is crucial to maintaining overall website security.

The vulnerability CVE-2026-56290 in Page Builder CK allows for unauthenticated arbitrary file uploads. This critical weakness arises due to improper validation of file uploads, enabling attackers to upload malicious executable files. Unchecked file uploads can lead to exploitation by allowing unauthorized users to execute these files, resulting in potential remote code execution. This vulnerability can make a site a target for attackers because of its widespread presence in Joomla sites using Page Builder CK. Security mechanisms that should typically prevent such uploads are bypassed, making this vulnerability particularly severe. Addressing this issue promptly is necessary to safeguard affected systems from exploitation.

The technical details of this vulnerability involve insufficient checks on files uploaded through the extension's interfaces. The specific vulnerable endpoint is located at '/index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture'. Malicious users can exploit this by sending a specially crafted HTTP POST request with multipart/form-data content type, permitting them to upload executable files. The system fails to check file types or extensions adequately, allowing potentially harmful files disguised as benign file types. Once uploaded, these files can be accessed and executed remotely, compromising the hosting server's security. The lack of proper security validations on the file paths and user permissions exacerbates the problem, increasing the vulnerability's severity.

If exploited, this vulnerability allows attackers to execute arbitrary code on the server unauthenticated, leading to full system takeover. Such breaches can pave the way for data theft, website defacement, and further exploitation, potentially affecting all sites hosted on the vulnerable server. Unchecked, this could lead to a loss of user trust, reputation damage, and significant recovery costs. It could also serve as an entry point for propagating malware or conducting further attacks on linked systems. To prevent such severe outcomes, immediate remediation of the vulnerability by updating or patching the software is necessary.

REFERENCES

Get started to protecting your digital assets