CVE-2026-56290 · Moderate · CISA KEV
Joomlack Page Builder RCE via Unauthenticated Arbitrary File Upload (KEV)
Threat Engine Auto-Feed · data current as of 2026-07-07
Joomlack Page Builder is affected by an improper access control vulnerability that enables unauthenticated arbitrary file upload, leading to remote code execution. This vulnerability is listed in CISA's KEV catalog, indicating active exploitation in the wild. Organizations using this product should prioritize patching.
- CVSS:
- EPSS percentile: 0.27626
- Exploitation pressure: 42/100 (Moderate)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 28th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
Improper access control means that the software does not correctly restrict who can perform certain actions. In this case, it allows unauthorized users to upload files, which can then be executed remotely.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using Joomlack Page Builder, especially those with public-facing web assets.
- Financial services and Technology sectors, given documented adversary targeting.
Misconfigurations that escalate it
- Lack of strict file upload validation and content-type enforcement.
- Insufficient network segmentation for web-facing applications.
High-impact scenarios
- An attacker gaining remote code execution on the server hosting Joomlack Page Builder.
- Data exfiltration, website defacement, or further network compromise originating from the compromised server.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor web server logs for unusual file uploads, especially to Joomlack Page Builder directories, from unauthenticated sources.
- Look for unexpected file types or executable files being uploaded to web-accessible paths.
- Implement web application firewall (WAF) rules to detect and block suspicious file upload attempts.
Contain
- Isolate affected Joomlack Page Builder instances from the rest of the network.
- Temporarily disable file upload functionality if feasible and necessary for containment.
- Review and revoke any unauthorized access or newly created accounts on the compromised system.
Patch
- Apply the latest security patches and updates for Joomlack Page Builder immediately.
- Ensure all Joomlack components and plugins are up-to-date.
Frontier verdict — Moderate
This vulnerability is actively exploited in the wild (CISA KEV) and allows unauthenticated remote code execution, making immediate patching critical for Joomlack Page Builder users.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.