HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Biztonsági rések & frissítési útmutatók
Új htprotect.app - Központi Joomla oldalkezelés több weboldalhoz
Biztonsági rés

Page Builder CK – critical upload flaw, actively exploited

KritikusCVSS 10.0 / 10 Aktívan kihasználjákCVE-2026-56290
Azonnali teendő
Update Page Builder CK to 3.6.0 or newer right away – the flaw is demonstrably being exploited.

Biztonságos verzió: Page Builder CK 3.6.0 or newer · via JoomlaCK

A lényeg röviden

Érintett bővítmény
Page Builder CK – page builder (com_pagebuilderck)
A biztonsági rés típusa
Unauthenticated file upload with no permission or file-type check → remote code execution (RCE)
Érintett verziók
All versions below 3.6.0 (Joomla 4 line below 3.4.10, Joomla 3 line below 3.1.1)
Biztonságos verzió
Page Builder CK 3.6.0 or newer   Letöltés
Súlyosság
Kritikus · CVSS 10.0 / 10 · aktívan kihasználják
Joomla-kompatibilitás
Joomla 3 / 4 / 5 / 6
Állapot / közzététel
Listed by CISA as actively exploited: 7 July 2026

Miről van szó?

Page Builder CK is a page builder for Joomla from the French vendor JoomlaCK. It has been around for years and comes in a free edition too, so it is widely deployed – often on sites without dedicated technical support.

One of its upload functions checked neither a login, nor permissions, nor the file type. An attacker could therefore place an executable file on the server without any access at all and then call it – which amounts to a full takeover of the site (CVE-2026-56290, severity 10 out of 10).

The US cyber security agency CISA has listed this flaw in its catalogue of actively exploited vulnerabilities since 7 July 2026. That is not a theoretical rating: being added there requires evidence of real attacks.

An important distinction: Page Builder CK (com_pagebuilderck) is not the same as SP Page Builder by JoomShaper (com_sppagebuilder). Both are page builders, both had critical flaws – but they are different products with different version numbers. Check in your back end which one you run.

Érintett az oldalam? – Így ellenőrizhető

  1. Open the back end

    Sign in to the Joomla administrator.

  2. Find the extension

    Open ExtensionsManageManage and filter for "Page Builder CK" or pagebuilderck.

  3. Assess the version

    If the version is below 3.6.0, the site is vulnerable. In the Joomla 4 line 3.4.10 is the safe release, in the Joomla 3 line 3.1.1.

  4. Look for signs of a break-in

    Search for unknown .php files in the extension’s media and upload folders, and for super user accounts you did not create yourself.

Így szüntethető meg a biztonsági rés

Frissítés előtt: biztonsági mentés
Frissítés előtt mentse el a fájlokat és az adatbázist – így hiba esetén bármikor visszaállítható a korábbi állapot (pl. az Akeeba Backup segítségével vagy a tárhelyszolgáltatónál).
  1. Before updating: back up

    Back up files and database before you update, so you can return if anything goes wrong.

  2. Open the update centre

    Go to SystemUpdateExtensions and click Check for updates.

  3. Update Page Builder CK

    Select the entry and update to 3.6.0 or newer.

  4. Verify the version

    Confirm that the new version is actually installed.

Kézi telepítés (alternatíva)
If no update appears, download the package directly from JoomlaCK and install it via ExtensionsManageInstall. Do not restore old files.

Hivatalos letöltési forrás: via JoomlaCK. A telepített verzió legyen legalább Page Builder CK 3.6.0 or newer.

Feltörték már a weboldalt?

Actively exploited – an update alone may not be enough
If the flaw was already used, the uploaded file is still on the server. The update only closes the way in. Check the upload and media folders for unknown PHP files, review the user list for unfamiliar super users, then change all passwords and block PHP execution in upload folders.

Segítségre van szüksége a kártékony kód eltávolításához? Megfelelő szakembereket a Joomla szolgáltatói jegyzékében talál.

Források & további hivatkozások

Minden esetben az adott fejlesztő hivatalos közlése az irányadó. Ez az oldal semlegesen foglalja össze a nyilvánosan elérhető információkat.

Supporters

Supporters of this site

htprotect.org is a free, vendor-independent information service. It is supported by:

Host & community
FC-Hosting

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.

fc-hosting.de
Initiator & operator
Website-Bereinigung.de

Specialised in cleaning, maintaining and securing Joomla and WordPress websites.

website-bereinigung.de

Support this project

You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.

Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.

Support HTProtect now
Bauschild & Service

Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.

bauschildundservice.de
IT Specialista

Professional IT support from Czechia – Windows management, domain administration and web hosting.

defendersoft.cz
onlineweg.de

Travel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.

onlineweg.de
Criadero

Creative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.

criadero.de
Jahn EDV-Dienst GmbH

IT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.

jahnedv.de
IsariConsult

Information-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.

isari-consult.de