VULNERABILITY OVERVIEW
An improper access control vulnerability in Joomlack's Page Builder CK for Joomla allows unauthenticated attackers to upload arbitrary executable files and achieve full remote code execution. Exploitation delivering web shells was observed as early as June 27, 2026, by the mySites.guru site management service. CISA added to KEV on July 7 with a federal patch deadline of July 10; update to Page Builder CK version 3.6.0 or later.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
Page Builder CK for Joomla versions prior to 3.6.0CITATIONS
- → https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
- → https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
- → https://threat-modeling.com/cve-2026-48908-cve-2026-56290-joomla-page-builders-cisa-kev/
- → https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/