Vulnerability record · CVE-2026-48907 · published 5 June 2026
CVE-2026-48907: JCE editor for Joomla allows unauthenticated profile creation and PHP upload
WWidgetfactorylimited · Jce
The JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. This is an improper access control flaw (CWE-284) rated CVSS 4.0 10.0 CRITICAL, and it is listed in CISA KEV, so it is being exploited in the wild.
Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:
Automated analysis
critical priorityCVSS 4.0 score of 10.0, unauthenticated remote code execution, KEV listing and very high EPSS probability make this an urgent patch-first issue.
What it is
The JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. This is an improper access control flaw (CWE-284) rated CVSS 4.0 10.0 CRITICAL, and it is listed in CISA KEV, so it is being exploited in the wild.
Impact
An unauthenticated attacker can upload and execute arbitrary PHP on the Joomla server, giving full control of the site and likely the underlying host. That enables data theft, defacement, persistence and use of the server as a foothold.
Attack surface
Reachable over the network with no authentication and no user interaction (CVSS 4.0 vector AV:N/PR:N/UI:N). Any internet-exposed Joomla site running the affected JCE extension is a candidate target.
Exploitation
Listed in CISA KEV with a due date of 2026-06-19, and EPSS 30-day probability is 0.781 (99.55th percentile), indicating active exploitation. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor security update for JCE as described in the vendor advisory; if the site cannot be patched, follow the vendor's free patch guidance for older sites.
- If no fix can be applied, take the Joomla site offline or block access to the JCE component endpoints until patched.
- Restrict or remove the JCE editor extension where it is not required.
- Review Joomla and JCE configuration for unauthorized editor profiles and remove any that are not expected.
- Follow CISA BOD 26-04 guidance and the KEV required action, including forensics triage for internet-exposed assets.
Detection
- Audit JCE editor profiles for entries created outside normal administrative workflows, especially recent or unexpected profiles.
- Monitor web server and Joomla logs for unauthenticated requests to JCE component endpoints that create profiles or upload files.
- Alert on newly written PHP files in Joomla web-accessible directories, particularly upload or media paths.
- Hunt for unexpected PHP execution or outbound connections from the Joomla host that follow JCE-related requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-48907 to the Known Exploited Vulnerabilities catalog on 16 June 2026 as "Widget Factory Joomla Content Editor Improper Access Control Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.joomlacontenteditor.net/ | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48907 | US Government Resource |
| https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites | Release NotesVendor Advisory |
Track CVE-2026-48907 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-48907), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.