Summary
A severe security flaw has been found in Page Builder CK, a popular free Joomla extension. This vulnerability allows an attacker to upload malicious files, like web shells, to your website without needing a username or password. This can give them full control over your site, allowing them to steal data, deface pages, or use your server for other attacks. The issue affects all versions of Page Builder CK up to and including 3.5.10. An urgent update to version 3.6.0 (or specific older versions for Joomla 3 and 4) is crucial. This flaw has already been actively exploited in real-world scenarios.
CVE Details
This critical vulnerability is officially identified as CVE-2026-56290. It was published on June 29, 2026, and discovered by Phil Taylor of mySites.guru. The vulnerability is categorized as CWE-284, which points to “Improper Access Control.” This means the software didn’t properly check who was trying to perform a sensitive action.
Affected Products
The vulnerability impacts the Joomla extension Page Builder CK, specifically:
- Versions up to and including 3.5.10 for current Joomla installations.
- Older Joomla 3 installations running Page Builder CK versions below 3.1.1.
- Joomla 4 installations running Page Builder CK versions below 3.4.10.
Current Status
This vulnerability has been analyzed and confirmed. Worryingly, within hours of the fix being released on June 27, 2026, attackers began actively exploiting this flaw in the wild. This highlights the urgent need for all affected website owners to take immediate action.
Severity Level
Rated with a CVSS 4.0 score of 10.0, this vulnerability is classified as CRITICAL. This is the highest possible severity rating, indicating that the flaw is easily exploitable and can lead to complete compromise of an affected website with no user interaction.
Possible Solutions
The most important step is to update your Page Builder CK extension immediately.
- Update Page Builder CK:
- For current Joomla versions, update to Page Builder CK 3.6.0 or newer.
- For Joomla 3 installations, update to Page Builder CK 3.1.1 or newer.
- For Joomla 4 installations, update to Page Builder CK 3.4.10 or newer.
You can usually perform this update through your Joomla administrator panel under “System” then “Update” and “Extensions.” If the update doesn’t appear, you can download the latest version from joomlack.fr and install it manually.
- Check for Compromise:
Updating the extension closes the vulnerability, but it won’t remove any malicious files already uploaded by an attacker. It’s vital to check your site for signs of compromise. Look for any suspicious.phpfiles, particularly within the/media/com_pagebuilderck/directory and its subfolders (likegfonts/). Also, broaden your search to other common web-served directories such as/images,/media,/templates, and/administrator. If you suspect your site might be compromised, refer to our guide on Joomla Hacked? for comprehensive cleanup steps. Check your Joomla “Users” list for any Super User accounts you don’t recognize. If you find any unauthorized files or users, assume your site has been compromised. In such cases, a thorough site cleanup, changing all Joomla passwords and secrets, and conducting a full security audit are essential steps. For more general advice on hardening your website, consult our Security Guide.
References
https://www.joomlack.fr/
https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3
https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/


