← Vulnerability feed

Vulnerability record · CVE-2026-48907 · published 5 June 2026

CVE-2026-48907: JCE editor for Joomla allows unauthenticated profile creation and PHP upload

WWidgetfactorylimited · Jce

The JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. This is an improper access control flaw (CWE-284) rated CVSS 4.0 10.0 CRITICAL, and it is listed in CISA KEV, so it is being exploited in the wild.

10.0 CVSS 4.0 Critical CISA KEV since 16 Jun 2026 EPSS 16% · top 3.2% CWE-284 · Improper access control
10.0CVSS 4.0 base score
16%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
23 Jul 2026Last modified by NVD

Description

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 score of 10.0, unauthenticated remote code execution, KEV listing and very high EPSS probability make this an urgent patch-first issue.

What it is

The JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. This is an improper access control flaw (CWE-284) rated CVSS 4.0 10.0 CRITICAL, and it is listed in CISA KEV, so it is being exploited in the wild.

Impact

An unauthenticated attacker can upload and execute arbitrary PHP on the Joomla server, giving full control of the site and likely the underlying host. That enables data theft, defacement, persistence and use of the server as a foothold.

Attack surface

Reachable over the network with no authentication and no user interaction (CVSS 4.0 vector AV:N/PR:N/UI:N). Any internet-exposed Joomla site running the affected JCE extension is a candidate target.

Exploitation

Listed in CISA KEV with a due date of 2026-06-19, and EPSS 30-day probability is 0.781 (99.55th percentile), indicating active exploitation. No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor security update for JCE as described in the vendor advisory; if the site cannot be patched, follow the vendor's free patch guidance for older sites.
  • If no fix can be applied, take the Joomla site offline or block access to the JCE component endpoints until patched.
  • Restrict or remove the JCE editor extension where it is not required.
  • Review Joomla and JCE configuration for unauthorized editor profiles and remove any that are not expected.
  • Follow CISA BOD 26-04 guidance and the KEV required action, including forensics triage for internet-exposed assets.

Detection

  • Audit JCE editor profiles for entries created outside normal administrative workflows, especially recent or unexpected profiles.
  • Monitor web server and Joomla logs for unauthenticated requests to JCE component endpoints that create profiles or upload files.
  • Alert on newly written PHP files in Joomla web-accessible directories, particularly upload or media paths.
  • Hunt for unexpected PHP execution or outbound connections from the Joomla host that follow JCE-related requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-48907 to the Known Exploited Vulnerabilities catalog on 16 June 2026 as "Widget Factory Joomla Content Editor Improper Access Control Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-48907 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-7339Widgetfactorylimited jce unrestricted file upload vulnerabilityJCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes…EPSS 1.1%6.5CVE-2026-65891Widgetfactorylimited jce improper input validation vulnerabilityJoomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE…EPSS 0.34%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed9.1CVE-2025-12480Gladinet Triofox improper access control exposes setup pagesTriofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Becaus…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2026-48907), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.