• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-56290: pre-auth remote code execution in Joomlack Page Builder

An unauthenticated attacker can upload arbitrary files to the Joomlack Page Builder extension and achieve remote code execution against vulnerable installations; this is tracked as CVE-2026-56290. The flaw affects Page Builder branch 1.x, versions 1.0 through 3.6.0 inclusive, and requires only network access to a Joomla instance running the vulnerable extension (no valid account or user interaction is needed). Exploitation enables full server compromise by placing and executing attacker-controlled files.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.30866
CWE
CWE-434
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added CVE-2026-56290 to its Known Exploited Vulnerabilities catalog with a July 10, 2026 remediation due date, and public exploit code is available, so immediately prioritize mitigating internet-exposed instances of the extension.

What is CVE-2026-56290?

An unauthenticated attacker can upload arbitrary files to the Joomlack Page Builder extension and achieve remote code execution against vulnerable installations; this is tracked as CVE-2026-56290. The flaw affects Page Builder branch 1.x, versions 1.0 through 3.6.0 inclusive, and requires only network access to a Joomla instance running the vulnerable extension (no valid account or user interaction is needed). Exploitation enables full server compromise by placing and executing attacker-controlled files. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Joomlack Page Builder are affected?

BRANCHAFFECTEDFIXED
1.x1.0-3.6.0

Is CVE-2026-56290 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-07, and U.S. federal agencies were required to remediate by 2026-07-10. Public exploit code is available.

How to fix CVE-2026-56290

  1. Remove or disable the Page Builder extension until a vendor fix is released.
  2. Isolate affected Joomla sites from untrusted networks and block access to the extension’s upload endpoints at the web application firewall or server level.
  3. Follow Joomlack vendor guidance for mitigations; if none are available, consider replacing the extension with a maintained alternative.
  4. Monitor web and application logs for suspicious file uploads and indicators of web shell activity; perform integrity checks and incident response if compromise is suspected.

Frequently asked questions

Is CVE-2026-56290 being actively exploited?

CISA added CVE-2026-56290 to the Known Exploited Vulnerabilities catalog on 2026-07-07, and public exploit code is available.

Which Page Builder versions are affected by CVE-2026-56290?

Joomlack Page Builder branch 1.x versions 1.0 through 3.6.0 are listed as affected.

Is there a patch for CVE-2026-56290?

No fixed version is listed in the supplied facts; a vendor patch is not yet indicated, so follow vendor mitigations or remove the extension.

Does CVE-2026-56290 require authentication?

No; the vulnerability allows unauthenticated arbitrary file upload and does not require a valid user account.

References