Widget Factory Joomla Content Editor Improper Access Control Vulnerability
joomlacontenteditor.net — Joomla Content Editor (JCE) extension for Joomla
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
9.8
78.1%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Jun 5, 2026
- Modified
- Jul 23, 2026
- Added to KEV
- Jun 16, 2026
- Federal patch due
- Jun 19, 2026
CISA required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2026-48907, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- gh1mau/masta-cve-2026-48907★ 59
cve-2026-48907 scanner
updated Aug 27, 2026
- ywh-jfellus/CVE-2026-48907★ 16
PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE
updated Aug 31, 2026
- K3ysTr0K3R/CVE-2026-48907★ 4
CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)
updated Aug 27, 2026
- 0xBlackash/CVE-2026-48907★ 3
CVE-2026-48907
updated Jun 29, 2026
- 0xgh057r3c0n/CVE-2026-48907★ 3
CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5
updated Aug 21, 2026
- pssec-io/CVE-2026-48907★ 1
POC for CVE-2026-48907
updated Jul 23, 2026
- sec0x/CVE-2026-48907★ 1
updated Aug 5, 2026
- ChiefYoru/CVE-2026-48907_PoC★ 1
Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla
updated Jul 19, 2026
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2026-48907?
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
How severe is CVE-2026-48907?
CVE-2026-48907 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2026-48907 actively exploited in the wild?
Yes. CVE-2026-48907 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Jun 16, 2026, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2026-48907?
78.1% - meaning FIRST.org's EPSS model estimates a 78.1% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2026-48907?
Yes - a public Nuclei template referencing CVE-2026-48907 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2026-48907?
CVE-2026-48907 is classified under CWE-284 (CWE-284 Improper Access Control).
Cross-checked against
Impactr finds and proves whether CVE-2026-48907 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist