What it is
CVE-2026-48907 is an unauthenticated vulnerability affecting joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla. A vulnerability in the JCE editor extension for Joomla allows the creation of new...
Vulnerability report
Joomla Content Editor (JCE) extension for Joomla Remote Code Execution
joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla · 1.0.0-2.9.99.4
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-48907 is an unauthenticated vulnerability affecting joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla. A vulnerability in the JCE editor extension for Joomla allows the creation of new...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla 1.0.0-2.9.99.4.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
Independent exploitation attestation added to the KEV Intelligence record.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2026-06-16 00:00 UTC |
| CVE | 2026-06-16 20:40 UTC |
| All CISA Advisories | 2026-06-16 21:20 UTC |
| TheHackerNews | 2026-06-17 07:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Nuclei template detected 15 Jun 2026.
View Nuclei template (opens in new tab)No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-48907.yaml | 15 Jun 2026 |
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
EPSS
68.8%
Recent mention · Rapid7
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like...
Read full advisoryRecent mention · Rapid7
Metasploit Wrap Up: Lot of summer shells and fit http profilesRapid7 · 14 Aug 2026
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog...
Recent mention · DarkWebInformer
Pre-Auth RCE in Joomla Content Editor: Profile Import to PHP Execution (CVE-2026-48907)DarkWebInformer · 17 Jun 2026
CVE-2026-48907 is a critical unauthenticated remote code execution flaw in the Joomla Content Editor (JCE), the most widely installed editor extension for Joomla.
Recent mention · TheHackerNews
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionTheHackerNews · 17 Jun 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-48907 (CVSS score: 10.0), is a case of improper access control that could facilitate arbitrary
Recent mention · All CISA Advisories
CISA Adds One Known Exploited Vulnerability to CatalogAll CISA Advisories · 16 Jun 2026
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces...
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
Exploitation attested by an external source
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Public proof-of-concept code published
Scanner coverage available
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-48907
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-48907",
"confidence": "Confirmed",
"cvss_score": 10.0,
"cvss_estimated": false,
"epss_score": 0.6883,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.