HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-48907Published Modified CNA Joomla

CVE-2026-48907: Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Metrics

CVSS v4.0
10.0
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an unauthenticated remote code execution vulnerability in the JCE (Joomla Content Editor) extension for Joomla, affecting all versions from 1.0.0 through 2.9.99.4. An attacker reachable over the network requires no credentials to exploit it: they create a new editor profile through an exposed endpoint and use it to upload and execute arbitrary PHP code on the server. Successful exploitation gives the attacker full control over the host, including reads, writes, and the ability to run operating-system commands. No fix has been published yet; HarborGuard tracks the advisory and will make a patched-image rebuild available the moment an upstream fix is released.

HarborGuard Coverage

Detection

Detection of CVE-2026-48907 is available across every HarborGuard environment. The CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images containing the JCE extension.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 10.0 (Critical) and weighting it against each environment's compliance policy. Routed alerts can be directed to the appropriate team inbox within each customer organization based on configured escalation rules.

Available
Patch

Because no fix version has been published, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. In the meantime, the finding is surfaced as an open critical-severity item in each affected environment's dashboard.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The vulnerable endpoint is exposed over the network, so the attacker must be able to send HTTP requests to the Joomla installation.

  • AuthenticationNot required

    No account or session token is needed; the profile-creation endpoint is accessible to unauthenticated users.

  • Victim interactionNot required

    The attacker operates entirely server-side; no user action or social-engineering step is required.

  • Attack complexityDetail

    Exploitation is reliable and condition-free: no race condition, memory layout dependency, or environmental prerequisite is involved.

Blast Radius

  • Attacker uploads and executes arbitrary PHP code, gaining a remote shell on the host running the Joomla application.
  • Full read access to the application filesystem, including configuration files, database credentials, and stored user data.
  • Full write access allows modification or deletion of site content, database records, and application files.
  • Compromise extends to systems and services reachable from the host, as indicated by high scores across both vulnerable and subsequent system impact dimensions in the CVSS v4 vector.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-48907 at this time, HarborGuard continuously monitors the advisory on every ingest cycle and will surface a patched-image rebuild as soon as joomlacontenteditor.net publishes a corrected release. While no patch is available, compensating controls worth considering include network-policy rules that restrict inbound HTTP access to the Joomla surface to known-good IP ranges, egress filtering to limit the blast radius of a compromised container, and disabling or removing the JCE extension entirely from images where rich-text editing is not required. For customers with auto-remediation enabled, a rebuilt image, regression-test run, and a pull request against affected workloads will be initiated automatically once a fix version is published.

See how HarborGuard automates this
Affected packages
  • joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla
    1.0.0-2.9.99.4
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red