S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jul 21, 2026

CVE-2026-56290 Scanner

CVE-2026-56290 Scanner - Unauthenticated Arbitrary File Upload vulnerability in Page Builder CK

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-56290
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
JoomlaCK.fr Page Builder CK extension for Joomlaby joomlack.fr
1.0-3.6.0
Updated Aug 19, 2026View on NVD →
Detail

Page Builder CK is a popular Joomla extension used by website developers to create and manage pages more efficiently. It is particularly common among individuals and businesses needing simple or advanced page layouts without extensive coding. With its drag-and-drop functionality, Page Builder CK enhances Joomla's flexibility and usability, allowing users to design unique web pages with ease. Organizations commonly rely on it to ensure their websites maintain professional aesthetics and functionality. Created by Joomlack, it has gained considerable adoption due to its user-friendly interface and customizable templates. However, keeping such extensions secure from vulnerabilities is crucial to maintaining overall website security.

The vulnerability CVE-2026-56290 in Page Builder CK allows for unauthenticated arbitrary file uploads. This critical weakness arises due to improper validation of file uploads, enabling attackers to upload malicious executable files. Unchecked file uploads can lead to exploitation by allowing unauthorized users to execute these files, resulting in potential remote code execution. This vulnerability can make a site a target for attackers because of its widespread presence in Joomla sites using Page Builder CK. Security mechanisms that should typically prevent such uploads are bypassed, making this vulnerability particularly severe. Addressing this issue promptly is necessary to safeguard affected systems from exploitation.

The technical details of this vulnerability involve insufficient checks on files uploaded through the extension's interfaces. The specific vulnerable endpoint is located at '/index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture'. Malicious users can exploit this by sending a specially crafted HTTP POST request with multipart/form-data content type, permitting them to upload executable files. The system fails to check file types or extensions adequately, allowing potentially harmful files disguised as benign file types. Once uploaded, these files can be accessed and executed remotely, compromising the hosting server's security. The lack of proper security validations on the file paths and user permissions exacerbates the problem, increasing the vulnerability's severity.

If exploited, this vulnerability allows attackers to execute arbitrary code on the server unauthenticated, leading to full system takeover. Such breaches can pave the way for data theft, website defacement, and further exploitation, potentially affecting all sites hosted on the vulnerable server. Unchecked, this could lead to a loss of user trust, reputation damage, and significant recovery costs. It could also serve as an entry point for propagating malware or conducting further attacks on linked systems. To prevent such severe outcomes, immediate remediation of the vulnerability by updating or patching the software is necessary.

REFERENCES

Solution Advice
  • Update Page Builder CK to the latest version to patch the vulnerability.
  • Implement strong file validation checks to prevent arbitrary file uploads.
  • Restrict file execution permissions on the server for unchecked files.
  • Regularly review and test security configurations on Joomla extensions.
  • Consider adding additional security layers such as Web Application Firewalls (WAF).

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.