CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Other sources
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48907?
CVE-2026-48907 has a critical severity rating of 10.
How do I fix CVE-2026-48907?
To fix CVE-2026-48907, upgrade the JCE extension to version 2.9.99.5 or later.
What impact does CVE-2026-48907 have on Joomla users?
CVE-2026-48907 allows unauthenticated users to create new editor profiles, leading to potential remote code execution.
Is my Joomla site vulnerable if I use an older version of the JCE extension?
Yes, any Joomla site using JCE versions prior to 2.9.99.5 is vulnerable to CVE-2026-48907.
Who is affected by CVE-2026-48907?
Any Joomla site utilizing the JCE extension prior to version 2.9.99.5 is affected by CVE-2026-48907.