Skip to content
COOEY

EXPOSURES › CVE-2026-56290

CVE-2026-56290

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-56290 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildsupply-chainzero-day

Joomlack Page Builder allows unauthenticated remote code execution via arbitrary file upload.

This vulnerability enables remote code execution through unauthenticated file uploads, posing a severe risk to any DIB organization using Joomlack Page Builder for FedRAMP or NIST 800-171 compliance. Immediate removal of the product from production environments and patching or replacement is required to prevent unauthorized code execution and potential data breaches.

Shame score — Unauthenticated RCE via file upload is a critical, avoidable security failure that directly compromises system integrity and confidentiality.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.