← Back to Feed

Joomlack Page Builder Improper Access Control Vulnerability

CVE-2026-56290

July 31, 2026 · CISA · Severity: CRITICAL

Joomlack Page Builder: Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. Vendor: Joomlack Product: Page Builder CISA Date Added: 2026-07-07 CVE: CVE-2026-56290 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2026-56290 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • The flaw enables remote code execution, allowing attackers to run arbitrary commands on affected systems.
  • CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
  • Joomlack Page Builder: Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
☕ Buy a Coffee