Critical RCE vulnerability in Widget Factory Joomla Content Editor (JCE) allows unauthenticated PHP code execution. Affects versions before 2.9.99.5.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| jce | * | 2.9.99.5 | vulnerable |
Immediately install the security patches provided by Widget Factory for the Joomla Content Editor extension to close the unauthorized profile creation vulnerability.
Verify all Joomla environments and upgrade JCE installations to version 2.9.99.5 or higher to ensure the vulnerable code is replaced.
Use a Web Application Firewall (WAF) to block external POST requests to JCE's profile management components and restrict administrative access to trusted IP ranges.
Inspect web logs for unauthorized profile creation events and scan the Joomla media and images directories for suspicious PHP files or web shells.
"Detecting exploitation of CVE-2026-48907 involves monitoring web server logs for suspicious POST requests to JCE's task-handling scripts, particularly those originating from unauthenticated sessions. Organizations should implement file integrity monitoring (FIM) to alert on the creation of PHP files within media upload directories. Additionally, review Joomla's database for any newly created editor profiles that do not align with known administrative actions or established change management records."
Experience superior visibility and a simpler approach to cyber risk management