Junglewise Threat Intelligence

CVE-2026-65891: joomlacontenteditor.net JCE file overwrite via rename function

CVE-2026-65891 · Severity: info · CVSS 0 · Published 2026-07-29

Executive brief

Joomla Content Editor (JCE), a popular content creation tool for the Joomla website platform, contains a flaw in its file management system. An authorized user with permissions to manage files could rename files in a way that creates hidden files or accidentally overwrites existing data. This could lead to data loss or the hiding of malicious files on the web server.

Technical details

An improper input validation vulnerability exists in the file rename functionality of Joomla Content Editor (JCE) versions prior to 2.20.2. An authenticated attacker with file management permissions can exploit this by providing specially crafted filenames that bypass validation checks. This allows for the creation of hidden files (e.g., files starting with a dot) or the unintended replacement of existing files at the destination path. The vulnerability is tracked as CWE-20 and was addressed in version 2.20.2.

Affected products

  • joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla 1.0.0 through 2.9.99.9 (versions prior to 2.20.2)

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References