Fix for critical vulnerability in JCE, a plugin for Joomla CMS

In JCE (Joomla Content Editor), one of the oldest and most popular extensions in the Joomla ecosystem, a critical vulnerability (CVE-2026-48907) has been fixed, allowing the import of a profile without authentication. An attacker can exploit this vulnerability to upload a profile that disables MIME type checking and executes PHP scripts on the server. There have been reports of this vulnerability being used by malicious actors to install a web shell, providing remote access to the system.

The vulnerability has been addressed in JCE version 2.9.99.5, followed by an update to 2.9.99.6 that enhances security. The vulnerability affects all versions of JCE (from Joomla 3 to Joomla 6). After applying the update, it is important to ensure that the system has not been compromised and that no backdoors installed by attackers remain.

To check for a rogue profile, which typically has a meaningless automatically generated name, you can find it in the administrator interface under "Components" — "JCE Editor" — "Editor Profiles." Also, ensure that PHP file uploads are not allowed in the "Allowed File Extensions" setting and check the logs for requests to the profile import URL (index.php?option=com_jce&task=profiles.import). The presence of third-party .htaccess and files with names typical for WordPress CMS, rather than Joomla, such as wp-config.php and wp-cron.php, may also indicate compromise.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster