Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
The Page Builder CK extension for Joomla contains an unauthenticated arbitrary file upload flaw that allows any remote attacker to place executable PHP files on the web server and then trigger them via HTTP, achieving full remote code execution without any credentials. All versions below 3.6.0 are affected. Active exploitation was observed within hours of the patch release, with web shells confirmed on live sites.
The extension exposes a file upload handler under the component's media directory that performs no authentication or authorization check before accepting files. The only nominal barrier is a CSRF token, but that token is readable from any public page of the site, making it trivially obtainable by any visitor. The handler also imposes no restriction on uploaded file types, satisfying both CWE-284 (missing access control on the endpoint) and CWE-434 (unrestricted upload of dangerous file types). Together these failures allow an unauthenticated caller to write a PHP webshell to any folder on the server.
An attacker reads a CSRF token from any public page of the target site, then sends a crafted HTTP POST to the upload handler containing a PHP webshell and a chosen destination folder path. Because the attacker controls the destination, the file can land outside the normal media directory rather than in a sandboxed images folder. The attacker then issues a GET request to the uploaded file's URL to execute arbitrary code. Confirmed post-exploitation artifacts include web shells placed at paths such as /media/com_pagebuilderck/gfonts/bhup.php. The result is full control of the Joomla web server: data exfiltration, defacement, persistent backdoor installation, or use of the server as a pivot.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Joomlack Page Builder runs inside your authorization boundary, CVE-2026-56290 is a direct concern for your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog, with a remediation deadline of July 10, 2026. An unpatched Known Exploited Vulnerability inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor or sponsoring agency raises it.
Knox does not patch Joomlack Page Builder on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-56290 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The patch is yours to apply; managing your compliance posture while you apply it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. That means exposure to something like CVE-2026-56290 surfaces during routine monitoring rather than waiting until an assessor flags it at review time, giving you more time to act before a deadline becomes a problem.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-56290 is not remediated by July 10, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









