Description
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
Published: 2026-07-22
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Page Builder CK extension for Joomla allows authenticated users to upload files without proper validation, enabling arbitrary code execution. This flaw corresponds to CWE-434 and can fully compromise confidentiality, integrity, and availability once exploited.

Affected Systems

Joomla sites using the joomlack.fr Page Builder CK extension, any version earlier than 3.6.2, are affected. The vulnerability was reported for all instances that have not applied the update.

Risk and Exploitability

The CVSS base score of 9.4 categorizes the issue as critical. The EPSS score of less than 1% suggests that exploit attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers must first gain authenticated access—such as administrators or users with content‑creation privileges—to upload a malicious file via the Page Builder CK extension. Once the file is uploaded, it can be executed directly, giving the attacker full control over the affected web server. The high severity and the inferred authenticated‑only attack path mean that a successful exploit would immediately provide an attacker with complete control of the target web server.

Generated by OpenCVE AI on August 4, 2026 at 00:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Page Builder CK to version 3.6.2 or later
  • If upgrade not possible, disable or restrict the file upload feature for non‑admin users
  • Implement restrictions on accepted file types or use server‑side validation to block executable uploads

Generated by OpenCVE AI on August 4, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.joomlack.fr/ cve-icon
History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Joomlack
Joomlack page Builder Ck Extension For Joomla
Vendors & Products Joomlack
Joomlack page Builder Ck Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
Title Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Joomlack Page Builder Ck Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:57:05.572Z

Reserved: 2026-07-15T08:12:23.736Z

Link: CVE-2026-63048

cve-icon Vulnrichment

Updated: 2026-07-22T12:50:14.419Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type