Executive brief
A critical security flaw has been identified in the Joomla Content Editor (JCE), a popular tool used to manage website content. This vulnerability allows unauthorized individuals to bypass security controls and upload malicious files to the web server. If exploited, an attacker could take complete control of the website, potentially leading to data theft, service disruption, or the installation of further malware. This issue is reportedly being actively exploited in the wild.
Technical details
An improper access control vulnerability (CWE-284) exists in the JCE editor extension for Joomla. The flaw allows unauthenticated remote attackers to create new editor profiles, which can then be leveraged to bypass file upload restrictions. By exploiting this, an attacker can upload and execute arbitrary PHP code on the server, leading to full remote code execution (RCE). The vulnerability is confirmed to be exploited in the wild, and users are advised to apply the security updates provided by the vendor immediately.
Affected products
- Widget Factory Joomla Content Editor (JCE) extension
Timeline
- 2026-06-05: disclosed
- 2026-06-16: advisory: NVD record updated with CISA-ADP enrichment
- 2026-06-16: exploited: Reported as exploited in the wild in advisory metadata