---
schema: 1
kind: vulnerability
title: "CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)"
headline: "CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)"
summary: "Unauthenticated CVSS-10 RCE in the Joomla Content Editor (JCE) is being exploited by automated tooling — CVE-2026-48907 lets an unauthenticated attacker abuse the JCE profile-import endpoint to upload and run PHP; CISA added it to the KEV catalog on 2026-06-16 and the vendor says unpatched sites should assume compromise (Widget Factory / JCE, 2026-06-03). Municipal/education Joomla portals across Europe are the exposed surface. See the Immediate Action below and § 2."
discovered_at: "2026-06-17T05:14:27Z"
event_date: 2026-06-16
run_id: 2026-06-17-e102009c
priority: critical
immediate_action:
  title: Patch or isolate internet-facing Joomla sites running the JCE editor now
  action: "CVE-2026-48907 is an unauthenticated, no-interaction remote-code-execution flaw (CVSS v4 10.0) in the Joomla Content Editor extension before version 2.9.99.5: an attacker POSTs to index.php?option=com_jce&task=profiles.import, imports a crafted editor profile that permits .php uploads, then drops a web shell — yielding code execution as the web-server user (Widget Factory / JCE, 2026-06-03). CISA added it to the KEV catalog on 2026-06-16 citing active exploitation, and the attacks are fully automated, so the absence of a public registration form is not protective (YesWeHack, 2026-06-16)."
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - rce
  - cisa-kev
regions:
  - global
sectors:
  - public-sector
  - education
entities: []
cves:
  - id: CVE-2026-48907
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites"
    publisher: "Widget Factory / JCE security update, 2026-06-03"
    role: primary
  - url: "https://www.yeswehack.com/news/rce-joomla-content-editor-extension"
    publisher: "YesWeHack — Unauthenticated RCE in the JCE extension, 2026-06-16"
    role: corroborating
  - url: "https://www.cisa.gov/news-events/alerts/2026/06/16/cisa-adds-one-known-exploited-vulnerability-catalog"
    publisher: "CISA — Adds one Known Exploited Vulnerability to Catalog, 2026-06-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: "The vulnerability is being actively exploited, working exploit code is public, and the attacks are automated, so a site with no public registration is not safe."
    publisher: Widget Factory / JCE
  - quote: The flaw allows attackers to create fake editor profiles without authentication and abuse the profile import functionality to upload and execute arbitrary PHP code on the server.
    publisher: YesWeHack
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-17.md
---

CVE-2026-48907 is an improper-access-control flaw (CWE-284) in the JCE extension — one of the most widely installed third-party Joomla editors — that chains three weaknesses in the profile-import workflow: a missing authentication check on `index.php?option=com_jce&task=profiles.import`, absent file-extension validation, and disabled upload-safety controls ([YesWeHack, 2026-06-16](https://www.yeswehack.com/news/rce-joomla-content-editor-extension)). An unauthenticated attacker imports a crafted editor profile that permits `.php` (or other executable) extensions for the Image Manager / File Browser plugin, then uploads a web shell that lands in `images/` by default — yielding OS-level code execution as the web-server user. The vendor states the attacks are fully automated and that a site without a public registration form is **not** safe; any site that ran a JCE version before 2.9.99.5 should assume compromise and restore from a pre-breach backup after confirming the timeline from web logs ([Widget Factory / JCE, 2026-06-03](https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites)). CISA added it to the KEV catalog on 2026-06-16. Patched in JCE version 2.9.99.5 (2026-06-03), further hardened in 2.9.99.6 (2026-06-06). Detection: unauthenticated POSTs to `profiles.import` in web logs; unfamiliar auto-named profiles at the top of the JCE profile list with PHP uploads enabled; unexpected PHP files in `images/`, `media/` or `tmp/`.


#### CVE Summary Table

Compact view of the actively-exploited / weaponised CVEs across this brief (full context in § 2 above and the § 4 updates).

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-48907 | Joomla Content Editor (JCE) before version 2.9.99.5 | 10.0 (v4) | n/a | Yes (06-16) | Yes — automated | version 2.9.99.5 (06-03) | [JCE](https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites) |
| CVE-2026-39808 | Fortinet FortiSandbox — JRPC OS command injection | 9.8 | n/a | No | Yes (06-15) | Apr 2026 (FG-IR-26-100) | [Help Net](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/) |
| CVE-2026-39813 | Fortinet FortiSandbox — JRPC path traversal / auth bypass | 9.1 | n/a | No | Yes (06-15) | Apr 2026 (FG-IR-26-112) | [Help Net](https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/) |
| CVE-2026-25089 | Fortinet FortiSandbox — web-UI command injection | 9.8 | n/a | No | Probable (faulty AI-built exploit) | 06-09 (FG-IR-26-141) | [Security Affairs](https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html) |
| CVE-2026-0257 | PAN-OS GlobalProtect — cookie auth bypass | 7.8 (v4) | n/a | Yes | Yes — since May 2026 | Vendor hotfixes | [PAN PSIRT](https://security.paloaltonetworks.com/CVE-2026-0257) |
| CVE-2026-50751 | Check Point Security Gateway — IKEv1 auth bypass | 9.3 | n/a | No | PoC public | Hotfix (early June) | [Help Net](https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/) |
