CVE-2026-48907

CRITICAL KEV NUCLEI LAB

Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-48907 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 16, 2026. EIP tracks 22 public exploits from researchers including ChiefYoru, amnsecurity, dyeat. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits an unauthenticated arbitrary file upload vulnerability in the Joomla JCE extension (CVE-2026-48907) to achieve remote code execution by uploading a PHP webshell. The exploit includes CSRF token extraction, mass exploitation capabilities, and thread-safe target processing.

Description

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Exploits (22)

github WORKING POC 1 stars
by ChiefYoru · pythonpoc
https://github.com/ChiefYoru/CVE-2026-48907_PoC

This PoC exploits an unauthenticated arbitrary file upload vulnerability in the Joomla JCE extension (CVE-2026-48907) to achieve remote code execution by uploading a PHP webshell. The exploit includes CSRF token extraction, mass exploitation capabilities, and thread-safe target processing.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla JCE Extension (unspecified version, but vulnerable to CVE-2026-48907)
No auth needed
Prerequisites: Joomla installation with vulnerable JCE extension · Target must have writeable /tmp/ directory · Network connectivity to target
mistral-large-3 · analyzed Jul 19, 2026 Full analysis →
github WORKING POC 1 stars
by amnsecurity · pythonpoc
https://github.com/amnsecurity/CVE-2026-48907-Joomla-JCE-RCE

This repository contains a functional Python exploit for CVE-2026-48907, an unauthenticated remote code execution vulnerability in Joomla's JCE Editor. The exploit creates a malicious editor profile allowing PHP file uploads, then uploads a web shell for command execution.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla CMS with JCE Editor (versions < 4.4.11, 5.x < 5.1.6)
No auth needed
Prerequisites: Target must have JCE Editor installed and accessible · PHP execution must be enabled on the server
mistral-large-3 · analyzed Jul 13, 2026 Full analysis →
github WORKING POC 1 stars
by dyeat · pythonpoc
https://github.com/dyeat/cve-reproduction/tree/main/Joomla/Joomla/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla Content Editor (JCE). The exploit uploads a malicious PHP file to the tmp/ directory via a CSRF-protected profile import feature and executes it.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla Content Editor (JCE) versions 1.0.0 to 2.9.99.4
No auth needed
Prerequisites: Joomla with vulnerable JCE version · Access to the target URL
mistral-large-3 · analyzed Jun 29, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/48xxx/CVE-2026-48907.md

This repository contains no actual exploit code or technical analysis for CVE-2026-48907. It only lists external GitHub repositories and an encrypted backup link, with no in-depth vulnerability details or functional PoC.

Classification
Suspicious 95%
Attack Type
Rce
Complexity
Unknown
Reliability
Unknown
Target: Joomla JCE extension < 2.9.99.5
No auth needed
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →
github WORKING POC
by bayu06802 · pythonremote
https://github.com/bayu06802/CVE-2026-48907

This exploit targets an unauthenticated remote code execution vulnerability in the JCE (Joomla Content Editor) extension for Joomla (< 2.9.99.5). It abuses the profile import functionality to upload arbitrary PHP files and achieve RCE via crafted XML payloads.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla! with JCE extension < 2.9.99.5
No auth needed
Prerequisites: JCE extension installed and accessible · Target Joomla instance must have writable /images/ or /tmp/ directory · CSRF token extraction from target
mistral-large-3 · analyzed Jul 04, 2026 Full analysis →
github WORKING POC
by NoXiVaR · pythonpoc
https://github.com/NoXiVaR/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, targeting Joomla's JCE component to achieve unauthenticated remote code execution (RCE) via profile import and file upload manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla with JCE (Joomla Content Editor) plugin
No auth needed
Prerequisites: Joomla instance with vulnerable JCE plugin · Network access to target
mistral-large-3 · analyzed Jul 01, 2026 Full analysis →
github WORKING POC
by pssec-io · phpremote
https://github.com/pssec-io/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla JCE. It includes a Dockerized lab environment, a PHP webshell, and step-by-step instructions to exploit the vulnerability via unauthenticated file upload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Joomla JCE ≤ 2.9.99.4
No auth needed
Prerequisites: Docker · Joomla JCE ≤ 2.9.99.4 installed
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →
github WORKING POC
by K3ysTr0K3R · pythonremote
https://github.com/K3ysTr0K3R/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla JCE. The exploit automates CSRF token extraction, malicious profile upload, and command execution via a PHP webshell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla Content Editor (JCE) Extension for Joomla (versions 1.0.0 through 2.9.99.4)
No auth needed
Prerequisites: Target running vulnerable JCE version · Network access to the Joomla instance
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →
github WORKING POC
by Almavj · pythonremote
https://github.com/Almavj/Joomla_CVE_2026_48907

This repository contains a functional Python-based scanner and exploit for CVE-2026-48907, targeting Joomla! JCE Editor versions below 2.9.99.5. The exploit verifies unauthenticated RCE by uploading a harmless PHP payload and confirming execution via a math-based verification mechanism.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla! JCE Editor < 2.9.99.5
No auth needed
Prerequisites: Joomla! instance with vulnerable JCE Editor version
mistral-large-3 · analyzed Jun 29, 2026 Full analysis →
nomisec WORKING POC
by xitexploiter96-dot · remote
https://github.com/xitexploiter96-dot/CVE-2026-48907-

This repository contains a functional Python-based exploit for CVE-2026-48907, targeting an unauthenticated RCE vulnerability in the Joomla JCE Editor. The exploit chain includes fingerprinting, CSRF token extraction, malicious profile import, and PHP payload upload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla JCE Editor < 2.9.99.5
No auth needed
Prerequisites: Joomla CMS with vulnerable JCE Editor extension · Network access to target
mistral-large-3 · analyzed Jun 29, 2026 Full analysis →
nomisec SCANNER
by grayxploit · remote
https://github.com/grayxploit/CVE-2026-48907

This repository contains a scanner for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla Content Editor (JCE) ≤ 2.9.99.4. The scanner detects the vulnerability by checking for missing authentication on the profiles.import endpoint and other conditions, but does not include exploit code for RCE.

Classification
Scanner 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla Content Editor (JCE) ≤ 2.9.99.4
No auth needed
Prerequisites: Access to the target Joomla instance · Network connectivity to the target
mistral-large-3 · analyzed Jun 27, 2026 Full analysis →
github SCANNER
by gh1mau · pythonremote
https://github.com/gh1mau/masta-cve-2026-48907

This repository contains a Python-based scanner for detecting CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla! JCE Editor versions below 2.9.99.5. The tool performs fingerprinting, WAF detection, and a math-verification payload test to confirm vulnerability presence.

Classification
Scanner 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla! JCE Editor < 2.9.99.5
No auth needed
Prerequisites: Target URL with Joomla! JCE Editor installed
mistral-large-3 · analyzed Jun 27, 2026 Full analysis →
nomisec WORKING POC
by 0xgh057r3c0n · remote
https://github.com/0xgh057r3c0n/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, targeting an unauthenticated arbitrary file upload vulnerability in Joomla! JCE extension versions below 2.9.99.5. The exploit demonstrates remote code execution by uploading a custom PHP file via a CSRF-protected endpoint, bypassing authentication.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla! JCE extension < 2.9.99.5
No auth needed
Prerequisites: Target running vulnerable Joomla! JCE extension · Network access to the target
mistral-large-3 · analyzed Jun 23, 2026 Full analysis →
github WORKING POC
by sec0x · pythonremote
https://github.com/sec0x/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, targeting a vulnerability in JCE (Joomla Content Editor). The exploit includes methods for token extraction, file upload, and command execution via SSI (Server-Side Includes) and PHP shells.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JCE (Joomla Content Editor) versions prior to 2.9.99.5
No auth needed
Prerequisites: Access to the target Joomla instance · JCE plugin installed and vulnerable
mistral-large-3 · analyzed Jun 22, 2026 Full analysis →
nomisec SCANNER
by g0thamRabb1t · poc
https://github.com/g0thamRabb1t/CVE-2026-48907-Joomla-JCE-detection

This repository contains Sigma rules for detecting exploitation attempts and post-exploitation activity related to CVE-2026-48907, a Joomla JCE component vulnerability. It includes detection logic for suspicious POST requests, webshell access, and anomalous process execution, but no functional exploit code.

Classification
Scanner 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla with JCE (Joomla Content Editor) component
No auth needed
Prerequisites: Joomla installation with vulnerable JCE component · Access to web server logs or auditd logs for detection
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →
github SCANNER
by g0thamRabb1t · poc
https://github.com/g0thamRabb1t/joomla-jce-cve-2026-48907-detection

This repository contains Sigma rules for detecting exploitation attempts and post-exploitation artifacts related to CVE-2026-48907, a vulnerability in the Joomla JCE component. It includes detection logic for web server logs and auditd events, but does not contain functional exploit code.

Classification
Scanner 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Joomla with JCE component
No auth needed
Prerequisites: Joomla installation with vulnerable JCE component · access to web server logs or auditd logs
mistral-large-3 · analyzed Jun 19, 2026 Full analysis →
github WORKING POC
by wearehackers160 · pythonremote
https://github.com/wearehackers160/CVE-2026-48907

This repository contains a functional Python exploit for CVE-2026-48907, an improper access control vulnerability in the JCE editor extension for Joomla. The exploit uploads a PHP payload (alfa.php) via a CSRF-protected endpoint and executes it to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JCE editor extension for Joomla
No auth needed
Prerequisites: Target URL · alfa.php payload file
mistral-large-3 · analyzed Jun 17, 2026 Full analysis →
nomisec WORKING POC
by HORKimhab · remote
https://github.com/HORKimhab/CVE-2026-48907

The repository contains multiple functional Python scripts that exploit CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla's JCE (Joomla Content Editor) component. The exploits automate the process of detecting JCE, importing malicious profiles, and uploading PHP webshells via the JCE file browser plugin.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla with JCE (Joomla Content Editor) plugin
No auth needed
Prerequisites: Joomla installation with JCE plugin · Network access to target
mistral-large-3 · analyzed Jun 17, 2026 Full analysis →
github WORKING POC
by 87achrafg-stack · pythonremote
https://github.com/87achrafg-stack/CVE-2026-48907

This repository contains a functional exploit for CVE-2026-48907, targeting an unauthenticated RCE vulnerability in Joomla's JCE (Joomla Content Editor) component. The exploit automates the process of detecting vulnerable installations, importing malicious profiles, and uploading PHP payloads to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla with JCE plugin
No auth needed
Prerequisites: Joomla installation with JCE plugin · Accessible /images/ directory for file uploads
mistral-large-3 · analyzed Jun 13, 2026 Full analysis →
github WRITEUP
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-48907

This repository provides a detailed technical analysis of CVE-2026-48907, an unauthenticated RCE vulnerability in JCE (Joomla Content Editor) caused by improper access control (CWE-284). It includes root cause analysis, exploitation flow, mitigation steps, and detection opportunities but does not contain actual exploit code.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: JCE (Joomla Content Editor) < 2.9.99.5
No auth needed
Prerequisites: Vulnerable JCE installation · Network access to the target
mistral-large-3 · analyzed Jun 12, 2026 Full analysis →
github WORKING POC
by ywh-jfellus · shellremote
https://github.com/ywh-jfellus/CVE-2026-48907

This repository contains a functional exploit PoC for CVE-2026-48907, targeting a Joomla vulnerability. The exploit demonstrates arbitrary file upload and remote code execution by uploading a malicious PHP file to the tmp/ directory and executing it.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla (specific version not specified)
Auth required
Prerequisites: CSRF token extraction · access to the Joomla admin interface
mistral-large-3 · analyzed Jun 11, 2026 Full analysis →
github WORKING POC
by webshellseo8 · pythonremote
https://github.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE

This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in JCE Joomla. The exploit automates the process of uploading malicious PHP payloads via the JCE editor's file upload functionality and verifies RCE by executing arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JCE (Joomla Content Editor) for Joomla
No auth needed
Prerequisites: Target must have JCE installed · JCE must be accessible and vulnerable
mistral-large-3 · analyzed Jun 09, 2026 Full analysis →

Nuclei Templates (1)

Joomla! JCE extension < 2.9.99.5 unauthenticated RCE
CRITICALVERIFIEDby ywh-jfellus
Shodan: http.component:"Joomla"
FOFA: app="Joomla"

Scores

CVSS v3 9.8
EPSS 0.8300
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Lab Environment

COMMUNITY SUSPICIOUS
Community Lab
docker pull joomla:latest
docker pull joomla:5.3.1-apache
+19 more repos

Details

CISA KEV 2026-06-16
VulnCheck KEV 2026-06-15
ENISA EUVD EUVD-2026-34789
CWE
CWE-284
Status published
Products (2)
joomlacontenteditor.net/Joomla Content Editor (JCE) extension for Joomla 1.0.0-2.9.99.4
widgetfactorylimited/jce < 2.9.99.5
Published Jun 05, 2026
KEV Added Jun 16, 2026
Tracked Since Jun 05, 2026