CVE-2026-65891: Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65891?
CVE-2026-65891 has a medium severity score of 6.5 on the CVSS scale.
How does CVE-2026-65891 affect Joomla users?
CVE-2026-65891 allows authenticated users with file management permissions to create hidden files and overwrite unintended files in Joomla Content Editor.
How do I fix CVE-2026-65891?
To fix CVE-2026-65891, update your Joomla Content Editor to version 2.9.99.10 or later.
Who is affected by CVE-2026-65891?
CVE-2026-65891 affects any Joomla installation using Joomla Content Editor versions prior to 2.9.99.10.
What is the underlying issue of CVE-2026-65891?
The underlying issue of CVE-2026-65891 is improper input validation in the file rename functionality.