CVE-2026-48907
A critical vulnerability in the JCE editor extension for Joomla allows unauthenticated users to create new editor profiles, which can lead to PHP code upload and execution. This flaw enables attackers to run arbitrary code on the affected site.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
The Joomla JCE editor extension (widgetfactorylimited jce) used by Joomla website administrators.
Real-world impact
An attacker can upload and execute arbitrary PHP code on the Joomla site, giving them full control over the server and its data.
Why this severity
The CVSS score of 10 reflects that the flaw is exploitable over the network, requires no authentication, and allows an attacker to gain complete control of the affected system. The high impact metrics (confidentiality, integrity, availability) and the ease of exploitation contribute to the critical rating.
What to do about it
- ›Follow vendor instructions to mitigate the vulnerability
- ›Follow CISA BOD 26-04 guidance and Forensics Triage Requirements
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
CISA KEV required action
Timeline
- Jun 5, 2026 · Jun 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jun 16, 2026 · Jun 16, 2026Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jun 19, 2026 · Jun 19, 2026CISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- joomlacontenteditor.netproduct
- cisa.gov/known-exploited-vulnerabili…us government resource
- joomlacontenteditor.net/news/jce-security-update-an…release notesvendor advisory