Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-48907

Published 2026-06-05
Updated 2 months ago
Vendor/s
Widget Factory
Product/s
Joomla Content Editor
Version/s
* > 2.9.99.5
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical RCE vulnerability in Widget Factory Joomla Content Editor (JCE) allows unauthenticated PHP code execution. Affects versions before 2.9.99.5.

CPE

Widget Factory logo
Widget Factory
Product Version Start Version End (excl.) Status
jce * 2.9.99.5 vulnerable

Related weakness (CWE)

CWE-284

Remediation plan

1

Apply official patches

Immediately install the security patches provided by Widget Factory for the Joomla Content Editor extension to close the unauthorized profile creation vulnerability.

2

Update affected systems

Verify all Joomla environments and upgrade JCE installations to version 2.9.99.5 or higher to ensure the vulnerable code is replaced.

3

Restrict access

Use a Web Application Firewall (WAF) to block external POST requests to JCE's profile management components and restrict administrative access to trusted IP ranges.

4

Monitor for exploitation

Inspect web logs for unauthorized profile creation events and scan the Joomla media and images directories for suspicious PHP files or web shells.

Detection Guidance

"Detecting exploitation of CVE-2026-48907 involves monitoring web server logs for suspicious POST requests to JCE's task-handling scripts, particularly those originating from unauthenticated sessions. Organizations should implement file integrity monitoring (FIM) to alert on the creation of PHP files within media upload directories. Additionally, review Joomla's database for any newly created editor profiles that do not align with known administrative actions or established change management records."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management