CVE-2026-48907

jce: Improper Access Control (CVE-2026-48907)

Severity
critical
Actively exploited
actively exploited (KEV)
99.6 %
Critical — model predicts very high exploitation likelihood in the next 30 days.
Published
2026-06-05 07:31 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 07:10 UTC· nvd@nist.gov
    • Translation: Title: extensión Joomla Content Editor (JCE) para Joomla, Description: Una vulnerabilidad en la extensión del editor JCE para Joomla permite la creación de nuevos perfiles de editor para usuarios no autenticados, lo que en última instancia resulta en la carga y ejecución de código PHP.
  2. CVE CISA KEV Update2026-06-17 16:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-06-16
    • Due Date: 2026-06-16
    • Required Action: 2026-06-16
    • Vulnerability Name: 2026-06-16

Description

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Source: CVELISTV5

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

Linked advisories