CVE-2026-48907

Published Jun 5, 2026

Last updated a month ago

Exploit knownCVSS critical 10.0
Zero-day
OT
JCE Editor Extension
Joomla

Overview

Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Source
security@joomla.org
NVD status
Analyzed
Products
jce

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Exploit added on
Jun 16, 2026
Exploit action due
Jun 19, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security@joomla.org
CWE-284

Social media

Hype score
Not currently trending
  1. Saxony’s data protection authority warns WordPress and Joomla operators about critical vulnerabilities. Key actions: 🩹 Patch CVE-2026-60137, CVE-2026-63030, and CVE-2026-48907 📣 Assess GDPR notification duties after unauthorized access Learn more: https://t.co/JpDcR5xp6

    @DataGuidance

    20 Aug 2026

    154 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-EDB-AWZes1i ( CVE-2026-48907 ) EGE-GH-86PDTBb ( CVE-2025-55182 ) EGE-GH-uET14Zz ( CVE-2026-20079 ) EGE-GH-voHgFaT ( CVE-2026-59310 ) EGE-GH-seDlYMs ( CVE-2026-59310 ) ..🧵👇

    @exploitgrid

    18 Aug 2026

    88 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-M3jqXW0 ( CVE-2024-3094 ) EGE-EDB-iFhaDfa ( CVE-2026-48907 ) EGE-GH-Ixgxp3b ( CVE-2025-59528 ) EGE-GH-eHXL7QB ( CVE-2024-8672 ) EGE-GH-CveopHx ( CVE-2025-2945 ) ..🧵👇

    @exploitgrid

    12 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Se detectó una campaña de Defacement que explota las vulnerabilidades CVE-2026-48907, CVE-2026-48908 y CVE-2026-49049 en Joomla!, dirigida a portales institucionales de Ecuador. Mas información: https://t.co/LRF4GLnOHP #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtE

    @EcuCERT_EC

    21 Jul 2026

    237 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-48907: 🚨 Critical 10.0 CVE-2026-48907 Unauthenticated RCE discovered in the Joomla Content Editor extension. 🤯🔥 PoC, advisory & technical breakdown are out. 🔗 Full analysis + resources 👇 📲 Telegram: #CyberSecurity #BugBounty…

    @lyrie_ai

    18 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2026-48907: ‼️🚨 A critical Joomla Content Editor vulnerability is under active attack and rated CVSS 10.0. Joomla is used by 1.2% of all websites on the internet. The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP,

    @lyrie_ai

    11 Jul 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. CVE-2026-48907. 0day Intel: 🚨 New critical improper access control vulnerability tagged CVE-2026-48907, aff

    @lyrie_ai

    11 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. 15:18 UTC: CVE-2026-48907 disclosed. Joomla Extension - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 CVE: CVE-2026-48907 PT ID: PT-2026-4

    @lyrie_ai

    8 Jul 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. CVE-2026-48907: Joomla Extension - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 CVE: CVE-2026-48907 PT ID: PT-2026-46908 Vendor: Joomla Product: Joomla Content Editor (JCE) extension for Joomla CVSS: 10 Credits: David Jardin Description: A vulnerability…

    @lyrie_ai

    8 Jul 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. マレーシア当局は6月26日、Joomla用コンテンツ編集拡張機能JCEの既知脆弱性CVE-2026-48907を悪用した攻撃により、複数の政府機関サイトが影響を受け、具体的な被害機関名も明らかになったと警告した。

    @yousukezan

    29 Jun 2026

    1559 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 1/6 🚨 Today’s top signals from the June 23 AI Security & Cyber Brief: • Joomla JCE RCE (CVE-2026-48907) – CISA added to KEV June 16. Actively exploited. Unauthenticated attackers upload PHP via profile import endpoint → full RCE on ≤2.9.99.4. Automated scans hitt

    @seoscottsdale

    23 Jun 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    6 Replies

    0 Quotes

  12. ⚠️ ثغرة بدرجة خطورة قصوى في إضافة Joomla Content Editor تحت استغلال فعلي تتيح رفع وتنفيذ شيفرة PHP دون مصادقة المعرّف : CVE-2026-48907 درجة الخطورة : 10.0 (CVSS) - Critical الإصدارا

    @KasperskyDev

    23 Jun 2026

    71 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. A critical Joomla Content Editor flaw is being mass exploited to deploy webshells. The @CISAgov added CVE-2026-48907 to KEV and gave agencies three days to patch. #cybersecurity #CISO #infosec https://t.co/lU0QwjjUWP

    @SCMagazine

    21 Jun 2026

    339 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Any site running the Joomla Content Editor can be taken over by unauthenticated attackers. CISA flagged CVE-2026-48907 (max severity 10.0) as actively exploited: create an editor profile, upload and run PHP code. Public exploit, automated attacks. Fix: JCE 2.9.99.5.

    @ShortInfoNews

    20 Jun 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. JCE (Joomla Content Editor) — Критическая уязвимость CVE-2026-48907 https://t.co/PlIc8WH38C #crimeakarro #karrolinux #itservicelinux

    @ASPbazi

    19 Jun 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2026-48907: How the Joomla JCE Exploit Works and What to Do About It: CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request. Here is how the attack works and how to check if your site… https://t.co/yDNHOJKoB

    @shah_sheikh

    18 Jun 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CISA warns of active exploitation of Joomla JCE vulnerability CVE-2026-48907. CVSS 10.0. Patch to 2.9.9 9.5 by June 19 or risk compromise. https://t.co/WyB59WiBD3 #CVE #Joomla #JCE #RCE #CVSS10 #KEVcatalog #CISA #WidgetFactory #JoomlaSecurity #WebShell https://t.co/J1RmT6XnOy

    @redsecuretech

    17 Jun 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 Joomla JCE Critical Alert CVE-2026-48907 is actively exploited and added to CISA KEV. ✅ Update JCE 2.9.99.5+ ✅ Check for web shells ✅ Review admin users https://t.co/WiLjn70k0f #CyberSecurity #Joomla #CVE #CISA #Vulert

    @vulert_official

    17 Jun 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Joomla JCE CVE-2026-48907 and LiteSpeed cPanel CVE-2026-54420 are being actively exploited, enabling file uploads, PHP execution, and possible root escalation on shared hosting servers. #Joomla #LiteSpeed #CISA https://t.co/o3etmdvGBO

    @TweetThreatNews

    17 Jun 2026

    192 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 JCE (Joomla Content Editor) is being actively exploited. CVE-2026-48907: unauthenticated attackers upload PHP webshells to any affected Joomla site. CISA added it to KEV on June 16. Federal patch due June 19. 🧵 #CVE #KEV https://t.co/9IdJYLDF1Z

    @cloudkey_tech

    17 Jun 2026

    5 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  21. CVE-2026-48907 - Joomla JCE Editor Unauthenticated RCE https://t.co/73oTMralti

    @d4rk_c0r3

    14 Jun 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2026-48907 - Joomla JCE Editor Unauthenticated RCE https://t.co/73oTMralti

    @d4rk_c0r3

    14 Jun 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 #CVE-2026-48907: Critical Unauthenticated RCE Flaw in Joomla Content Editor – Patch Now! + Video https://t.co/A68xFugiLJ Educational Purposes!

    @UndercodeUpdate

    14 Jun 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 CVE-2026-48907 - critical 🚨 Joomla! JCE extension < 2.9.99.5 unauthenticated RCE > Joomla JCE editor extension contains an unrestricted file upload vulnerability caused... 👾 https://t.co/50fCeQphBb @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    13 Jun 2026

    176 Impressions

    1 Retweet

    0 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

Configurations