DIRAS TAKE
Urgent: CISA added CVE-2026-56290 to its Known Exploited Vulnerabilities catalog with a July 10, 2026 remediation due date, and public exploit code is available, so immediately prioritize mitigating internet-exposed instances of the extension.
What is CVE-2026-56290?
An unauthenticated attacker can upload arbitrary files to the Joomlack Page Builder extension and achieve remote code execution against vulnerable installations; this is tracked as CVE-2026-56290. The flaw affects Page Builder branch 1.x, versions 1.0 through 3.6.0 inclusive, and requires only network access to a Joomla instance running the vulnerable extension (no valid account or user interaction is needed). Exploitation enables full server compromise by placing and executing attacker-controlled files. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Joomlack Page Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0-3.6.0 |
Is CVE-2026-56290 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-07, and U.S. federal agencies were required to remediate by 2026-07-10. Public exploit code is available.
How to fix CVE-2026-56290
- Remove or disable the Page Builder extension until a vendor fix is released.
- Isolate affected Joomla sites from untrusted networks and block access to the extension’s upload endpoints at the web application firewall or server level.
- Follow Joomlack vendor guidance for mitigations; if none are available, consider replacing the extension with a maintained alternative.
- Monitor web and application logs for suspicious file uploads and indicators of web shell activity; perform integrity checks and incident response if compromise is suspected.
Frequently asked questions
Is CVE-2026-56290 being actively exploited?
CISA added CVE-2026-56290 to the Known Exploited Vulnerabilities catalog on 2026-07-07, and public exploit code is available.
Which Page Builder versions are affected by CVE-2026-56290?
Joomlack Page Builder branch 1.x versions 1.0 through 3.6.0 are listed as affected.
Is there a patch for CVE-2026-56290?
No fixed version is listed in the supplied facts; a vendor patch is not yet indicated, so follow vendor mitigations or remove the extension.
Does CVE-2026-56290 require authentication?
No; the vulnerability allows unauthenticated arbitrary file upload and does not require a valid user account.
References
- nvd.nist.gov/vuln/detail/CVE-2026-56290
- cve.org/CVERecord?id=CVE-2026-56290
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56290
- joomlack.fr
- All Joomlack CVEs on CVE Radar
- CVEs published in September 2026