What is CVE-2026-56290?
CVE-2026-56290 is an improper access control vulnerability in the Joomlack Page Builder plugin. It could allow remote code execution via unauthenticated arbitrary file upload. Users are advised to immediately update the plugin or temporarily disable it.
Azərbaycanca: CVE-2026-56290 Joomlack Page Builder plagini üçün düzgün olmayan giriş nəzarəti zəifliyidir. Bu zəiflik autentifikasiya olunmamış ixtiyari fayl yükləməsi vasitəsilə uzaqdan kod icrasına (RCE) imkan verə bilər. İstifadəçilər dərhal plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq söndürməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
How can I identify the plugin affected by CVE-2026-56290?
This vulnerability specifically affects the Joomlack Page Builder plugin. If you have this plugin installed, you should immediately update it to the latest version or temporarily disable it.
What can the exploitation of CVE-2026-56290 lead to?
Successful exploitation of this improper access control vulnerability could allow remote code execution via unauthenticated arbitrary file upload.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.