← Back to Feed
Joomlack Page Builder Improper Access Control Vulnerability
CVE-2026-56290
July 31, 2026 · CISA · Severity: CRITICAL
Joomlack Page Builder: Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Vendor: Joomlack
Product: Page Builder
CISA Date Added: 2026-07-07
CVE: CVE-2026-56290
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2026-56290 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The flaw enables remote code execution, allowing attackers to run arbitrary commands on affected systems.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Joomlack Page Builder: Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.