Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Joomlack Page Builder Could Let Hackers Take Over Your Website

A serious security weakness has been found in the Joomlack Page Builder extension for Joomla websites. This flaw allows attackers to upload harmful files without logging in, potentially taking full control of the website. Because this vulnerability is actively being exploited, it is important for organisations using this software to act quickly.

08 July 2026

Reference: CVE-2026-56290

1. What is being reported?

The Joomlack Page Builder extension for Joomla has a security problem that lets anyone upload files that can run harmful code on your website without needing a username or password. This means hackers can take over your site remotely.

2. What this means in plain English

If your website uses this extension, hackers could gain full control, steal data, or cause damage. This is a high-risk issue because it does not require the attacker to be logged in, making it easier to exploit.

3. Could this affect a small business?

Small businesses, charities, clubs, or any organisation using the Joomlack Page Builder on their Joomla website could be affected. If you do not use this extension or Joomla, this vulnerability does not apply to you.

4. What to do now

  • Check if your website uses the Joomlack Page Builder extension.
  • Contact your IT provider or website manager immediately to apply any available security updates or mitigations from the vendor.
  • If no fix is available, consider disabling or removing the extension until it is safe to use.
  • Review your website’s security and monitor for any unusual activity.

5. Ask your IT provider

Can you confirm if our Joomla website uses the Joomlack Page Builder extension, and if so, have the latest security updates or mitigations been applied to protect against CVE-2026-56290?

6. Bottom line

If you use Joomlack Page Builder on your Joomla site, act now to prevent hackers from taking control.

Information based on CISA KEV, NVD, and reputable security reports.

Back to Vulnerability Briefs