CVE-2026-48907
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
In plain language
AI Act nowJoomla’s JCE (Content Editor) extension has a critical flaw where an attacker with no login can upload and run malicious code on your site; if you use Joomla with JCE and it’s older than 2.9.99.5, you should act immediately—this is already being exploited.
CVE-2026-48907 is an unauthenticated remote code execution flaw in the Joomla Content Editor (JCE) extension caused by improper access control that lets an attacker create new editor profiles, which then enables PHP code upload and execution (active exploitation confirmed via CISA KEV).
What to do now
- Check whether your Joomla site uses the Joomla Content Editor (JCE) extension and determine its current JCE version.
- If your JCE version is older than 2.9.99.5, plan an immediate update to the fixed release.
- Upgrade JCE to version 2.9.99.5 or later (the fixed version listed for this issue).
- If you cannot update right away, follow Joomla/JCE guidance to reduce exposure as instructed by the vendor and CISA (and treat the site as potentially compromised).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
References
- Metasploit Wrap Up: Lot of summer shells and fit http profilesen·Rapid7 Blog· PoC Metasploit rce
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Daysen·The Hacker News· Exploited Balbooa Forms web-app
- Australia warns of global campaign targeting vulnerable CMS platformsen-us·BleepingComputer· Exploited Simple File List web-app
- Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sitesen·The Hacker News· Exploited WordPress malware
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and Moreen·The Hacker News· Roundup Fortinet FortiGate Icarus
- 2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)en-us·Daily CyberSecurity (securityonline.info)· Exploited Splunk Enterprise zero-day
- CISA orders feds to patch max severity Joomla plugin flaw by Fridayen-us·BleepingComputer· Exploited Widget Factory Joomla Content Editor (JCE) plugin web-app
- Joomla, LiteSpeed Vulnerabilities Exploited in Attacksen-us·SecurityWeek· Exploited Joomla Content Editor (JCE) Pro rce
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Executionen·The Hacker News· Exploited Widget Factory Joomla Content Editor (JCE) rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48907 and every CVE in our database. Create a free account — no credit card required.
Create Free Account