← back
CVE-2026-48907criticalunder attackCWE-284

Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 10epss 56%
from disclosure to weapon4 days
Published on NVDJun 5
1st PoC+4d
metasploitJun 5
CISA KEV+11d
exploitation probability
56%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
34 public exploit(s)
Action required by CISAfederal deadline: 2026-06-19

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
public PoCs found34
githubgithub.com/gh1mau/masta-cve-2026-4890757githubgithub.com/ywh-jfellus/CVE-2026-4890715githubgithub.com/0xgh057r3c0n/CVE-2026-489074githubgithub.com/0xBlackash/CVE-2026-489073githubgithub.com/K3ysTr0K3R/CVE-2026-489072githubgithub.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE1githubgithub.com/sec0x/CVE-2026-489071githubgithub.com/pssec-io/CVE-2026-489071githubgithub.com/g0thamRabb1t/CVE-2026-48907-Joomla-JCE-detection1githubgithub.com/amnsecurity/CVE-2026-48907-Joomla-JCE-RCE1githubgithub.com/ChiefYoru/CVE-2026-48907_PoC1githubgithub.com/xitexploiter96-dot/CVE-2026-48907-0githubgithub.com/Almavj/Joomla_CVE_2026_489070githubgithub.com/87achrafg-stack/CVE-2026-489070githubgithub.com/bayu06802/CVE-2026-489070githubgithub.com/NoXiVaR/CVE-2026-489070githubgithub.com/HORKimhab/CVE-2026-489070githubgithub.com/g0thamRabb1t/joomla-jce-cve-2026-48907-detection0githubgithub.com/wearehackers160/CVE-2026-489070githubgithub.com/grayxploit/CVE-2026-489070vulncheckvulncheck.com/xdb/f459dd355b00unverifiedvulncheckvulncheck.com/xdb/30044911c5a5unverifiedvulncheckvulncheck.com/xdb/c0936cc796c9unverifiedvulncheckvulncheck.com/xdb/609673988f8eunverifiedvulncheckvulncheck.com/xdb/584961b43d7cunverifiedvulncheckvulncheck.com/xdb/7b5f88d13907unverifiedvulncheckvulncheck.com/xdb/c8ea4f263e83unverifiedvulncheckvulncheck.com/xdb/df10c0c1a5fbunverifiedvulncheckvulncheck.com/xdb/ba4be0ffd1eeunverifiedvulncheckvulncheck.com/xdb/f624442bb47cunverifiedvulncheckvulncheck.com/xdb/8f852dc50830unverifiedvulncheckvulncheck.com/xdb/8aea764423e4unverifiedvulncheckvulncheck.com/xdb/d0682c028430unverifiedvulncheckvulncheck.com/xdb/3346a89083f0unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.