ctipilot.ch

Widget Factory Joomla Content Editor (JCE) <2.9.99.5 — unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV

cve · CVE-2026-48907

Coverage timeline
2
first 2026-06-17 → last 2026-06-22
Peak priority
critical
1 critical · 1 notable
Sources cited
7
6 hosts
Sections touched
2
trending-vulnerabilities, weekly-vuln-rollup
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-22CVE-2026-48907 — Joomla Content Editor (JCE): unauthenticated profile-import to PHP RCE (CVSS 4.0 10.0, CISA KEV)
    weekly-vuln-rollup
  2. 2026-06-17CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • weekly-vuln-rollup1

Source distribution

  • helpnetsecurity.com2 (29%)
  • cisa.gov1 (14%)
  • joomlacontenteditor.net1 (14%)
  • security.paloaltonetworks.com1 (14%)
  • securityaffairs.com1 (14%)
  • yeswehack.com1 (14%)

explore in graph

Entries about Widget Factory Joomla Content Editor (JCE) <2.9.99.5 — unauthenticated profile-import to PHP RCE (CVSS v4 10.0); CISA KEV (2)

2026-06-22 · view entry permalink →

NOTABLECVE-2026-48907exploited

CVE-2026-48907 — Joomla Content Editor (JCE): unauthenticated profile-import to PHP RCE (CVSS 4.0 10.0, CISA KEV)

JCE is one of the most widely installed Joomla editors across European universities, municipalities and community portals. CVE-2026-48907 chains weaknesses in the profile-import workflow into unauthenticated PHP remote code execution, is rated CVSS 4.0 10.0, and was KEV-listed on 2026-06-16 (Widget Factory / JCE; YesWeHack; daily 06-17). Update to JCE 2.9.99.5 or later; the vendor also shipped a free patch for older sites.

JCE is one of the most widely installed Joomla editors across European universities, municipalities and community portals.

ctipilot v2 brief (migrated)
vulnerability22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-17 · view entry permalink →

CRITICALCVE-2026-48907exploited

CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)

CVE-2026-48907 is an improper-access-control flaw (CWE-284) in the JCE extension — one of the most widely installed third-party Joomla editors — that chains three weaknesses in the profile-import workflow: a missing authentication check on index.php?option=com_jce&task=profiles.import, absent file-extension validation, and disabled upload-safety controls (YesWeHack, 2026-06-16). An unauthenticated attacker imports a crafted editor profile that permits .php (or other executable) extensions for the Image Manager / File Browser plugin, then uploads a web shell that lands in images/ by default — yielding OS-level code execution as the web-server user. The vendor states the attacks are fully automated and that a site without a public registration form is not safe; any site that ran a JCE version before 2.9.99.5 should assume compromise and restore from a pre-breach backup after confirming the timeline from web logs (Widget Factory / JCE, 2026-06-03). CISA added it to the KEV catalog on 2026-06-16. Patched in JCE version 2.9.99.5 (2026-06-03), further hardened in 2.9.99.6 (2026-06-06). Detection: unauthenticated POSTs to profiles.import in web logs; unfamiliar auto-named profiles at the top of the JCE profile list with PHP uploads enabled; unexpected PHP files in images/, media/ or tmp/.

CVE Summary Table

Compact view of the actively-exploited / weaponised CVEs across this brief (full context in § 2 above and the § 4 updates).

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-48907 Joomla Content Editor (JCE) before version 2.9.99.5 10.0 (v4) n/a Yes (06-16) Yes — automated version 2.9.99.5 (06-03) JCE
CVE-2026-39808 Fortinet FortiSandbox — JRPC OS command injection 9.8 n/a No Yes (06-15) Apr 2026 (FG-IR-26-100) Help Net
CVE-2026-39813 Fortinet FortiSandbox — JRPC path traversal / auth bypass 9.1 n/a No Yes (06-15) Apr 2026 (FG-IR-26-112) Help Net
CVE-2026-25089 Fortinet FortiSandbox — web-UI command injection 9.8 n/a No Probable (faulty AI-built exploit) 06-09 (FG-IR-26-141) Security Affairs
CVE-2026-0257 PAN-OS GlobalProtect — cookie auth bypass 7.8 (v4) n/a Yes Yes — since May 2026 Vendor hotfixes PAN PSIRT
CVE-2026-50751 Check Point Security Gateway — IKEv1 auth bypass 9.3 n/a No PoC public Hotfix (early June) Help Net

The vulnerability is being actively exploited, working exploit code is public, and the attacks are automated, so a site with no public registration is not safe.

Widget Factory / JCE

The flaw allows attackers to create fake editor profiles without authentication and abuse the profile import functionality to upload and execute arbitrary PHP code on the server.

YesWeHack
vulnerability17 Jun 05:14Zmulti-sourceOpen finding ↗