Knox CVE Database
/
CVE-2026-48907
Critical
9.8

CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

Added to the CISA KEV catalog:
June 16, 2026

Overview

The JCE editor extension for Joomla contains an improper access control flaw that exposes a profile import endpoint to unauthenticated HTTP requests. Any remote attacker can send a crafted request to create a malicious editor profile that permits PHP file uploads, then upload a webshell to a publicly accessible directory, achieving full remote code execution on the server. All JCE versions prior to 2.9.99.5 are affected. The vulnerability is actively exploited by automated attacks, and working exploit code is publicly available.

Vulnerability details

Affected vendor
Widget Factory
Affected product
Joomla Content Editor
Weakness type (CWE)
CWE-284

The JCE extension fails to enforce authentication on its profile import endpoint, a classic improper access control failure (CWE-284). Administrative functions that create or modify editor profiles should require a valid authenticated session; instead, the endpoint accepts requests from any unauthenticated caller. An attacker can supply a crafted profile configuration that sets permitted file extensions to include PHP, bypassing the upload restrictions that legitimate profiles enforce. Once the rogue profile exists on the site, it becomes available as an upload context, and the attacker can use it to place executable files in directories served by the web server.


An attacker sends two sequential unauthenticated HTTP requests: the first targets the profile import endpoint at index.php?option=com_jce&task=profiles.import to create a profile permitting PHP uploads; the second uploads a PHP webshell through that profile, typically landing in the images folder. The result is unauthenticated remote code execution on the Joomla server. No prior account, registration, or user interaction is required, and the vendor confirms attacks are fully automated. Sites with no public registration are not protected. Updating closes the entry point but does not remove files or profiles an attacker already placed before the patch was applied.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review web server access logs for unauthenticated POST requests to index.php?option=com_jce&task=profiles.import. Any such request from an external IP is a strong indicator of exploitation; the earliest matching entry establishes the breach window.
  • Audit Components > JCE Editor > Editor Profiles for profiles you did not create, particularly those with auto-generated names, unusual ordering, or permitted file extensions that include PHP or other executable types.
  • Inspect the images, media, and tmp directories for PHP files or files with PHP embedded in the filename (e.g., foo.php.xml). These directories should contain no PHP files under normal operation; any found there warrant immediate investigation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 19, 2026

Additional hardening

  • Upgrade JCE to version 2.9.99.5 or later; the vendor recommends 2.9.99.9. Sites unable to meet the PHP 7.4 and Joomla 3.9 requirements for 2.9.99.9 should apply the vendor-supplied free patch package for JCE 2.7.x, 2.8.x, and 2.9.x.
  • If immediate patching is not possible, configure your web server or WAF to block unauthenticated requests to the path index.php?option=com_jce&task=profiles.import at the perimeter, preventing the initial profile creation step.
  • Restrict PHP execution in the images, media, and tmp directories via web server configuration (e.g., deny PHP handler for those paths), so that even if a webshell is uploaded it cannot be executed.
  • After patching, treat any site that was exposed before the update as potentially compromised: audit profiles, scan for unexpected PHP files, rotate all administrator and database credentials, and restore from a pre-breach backup if logs confirm exploitation.

Key dates

Published (NVD)
June 5, 2026
Added to CISA KEV
June 16, 2026
Remediation deadline
June 19, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-48907 affect my FedRAMP authorization?

If Widget Factory Joomla Content Editor runs inside your authorization boundary, yes. CVE-2026-48907 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 19, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can already see. Your options now are to remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-48907?

Knox does not patch Widget Factory Joomla Content Editor on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to carry out. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including something like CVE-2026-48907. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the earliest possible opportunity to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-48907's remediation deadline of June 19, 2026 has passed. What happens now?

An unremediated CVE-2026-48907 is already a Plan of Action and Milestones (POA&M) item, and a growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and documenting why the deadline was missed is what keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting