CVE-2026-56290 — Joomlack Page Builder Improper Access Control Vulnerability
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
- CVSS
- 9.8 (Critical)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — patch or disable within 48 hours; treat every Joomla site running the extension as suspect until proven clean.
- Vendor advisory
- https://www.joomlack.fr/en/joomla-extensions/page-builder-ck
- Affected products
- Joomlack Page Builder
Why this one matters to a CAB
Joomlack Page Builder is a smaller-installed-base cousin of the JoomShaper builder in CVE-2026-48908, but the vulnerability class is the same and the CISA due date is the same. Anywhere a Joomla site is running any third-party page builder, the CAB should demand an inventory this week.
Defender’s angle
- Inventory-first: this is not one CVE, it is a family of Joomla-extension file-upload weaknesses hitting KEV in the same window. Standing up a monthly Joomla-extension inventory job is a durable win from this CVE.
- Extension pinning: the CAB should recommend a policy that Joomla sites cannot install third-party extensions outside the approved list without a security review.
- Post-patch scan: same webshell-search step described in CVE-2026-48939.
What to bring to CAB
A change record that includes a proposal for the Joomla extension governance policy. Fixing this one CVE without fixing the class is theater.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.