What the vulnerability does
01Description
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
Explanation of Vulnerability in Simple Terms
02Summary
Page Builder CK extension for Joomla contains an unrestricted file upload vulnerability. An authenticated user with low privileges can upload arbitrary files to the server, potentially including executable code. This allows attackers to run their own PHP code on the site and take full control. The vulnerability affects versions 1.0.0 through 3.6.2.
What an attacker can do
03Attacker Capabilities
Upload arbitrary files, including executable code, to run PHP on the site.
Potential impact on your site
04Site Impact
Compromised Joomla site; attacker gains ability to modify content, steal data, or inject malware.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege Joomla user account (e.g., contributor or editor role).
Key dates
06Disclosure timeline
July 22, 2026
CVE published
August 26, 2026
Record updated