← voltar
CVE-2026-48907criticalsob ataqueCWE-284

Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 10epss 56%
da publicação à arma4 dias
Publicada no NVD5 de jun.
1ª PoC+4d
metasploit5 de jun.
CISA KEV+11d
probabilidade de exploração
56%top 1% das CVEs
exploração observada
simCISA + VulnCheck
34 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2026-06-19

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
PoCs públicas encontradas34
githubgithub.com/gh1mau/masta-cve-2026-4890757githubgithub.com/ywh-jfellus/CVE-2026-4890715githubgithub.com/0xgh057r3c0n/CVE-2026-489074githubgithub.com/0xBlackash/CVE-2026-489073githubgithub.com/K3ysTr0K3R/CVE-2026-489072githubgithub.com/ChiefYoru/CVE-2026-48907_PoC1githubgithub.com/webshellseo8/CVE-2026-48907-Unauthenticated-RCE-in-JCE1githubgithub.com/pssec-io/CVE-2026-489071githubgithub.com/amnsecurity/CVE-2026-48907-Joomla-JCE-RCE1githubgithub.com/sec0x/CVE-2026-489071githubgithub.com/g0thamRabb1t/CVE-2026-48907-Joomla-JCE-detection1githubgithub.com/NoXiVaR/CVE-2026-489070githubgithub.com/HORKimhab/CVE-2026-489070githubgithub.com/bayu06802/CVE-2026-489070githubgithub.com/87achrafg-stack/CVE-2026-489070githubgithub.com/g0thamRabb1t/joomla-jce-cve-2026-48907-detection0githubgithub.com/wearehackers160/CVE-2026-489070githubgithub.com/grayxploit/CVE-2026-489070githubgithub.com/xitexploiter96-dot/CVE-2026-48907-0githubgithub.com/Almavj/Joomla_CVE_2026_489070vulncheckvulncheck.com/xdb/c0936cc796c9não verificadovulncheckvulncheck.com/xdb/8aea764423e4não verificadovulncheckvulncheck.com/xdb/8f852dc50830não verificadovulncheckvulncheck.com/xdb/f624442bb47cnão verificadovulncheckvulncheck.com/xdb/609673988f8enão verificadovulncheckvulncheck.com/xdb/ba4be0ffd1eenão verificadovulncheckvulncheck.com/xdb/df10c0c1a5fbnão verificadovulncheckvulncheck.com/xdb/c8ea4f263e83não verificadovulncheckvulncheck.com/xdb/584961b43d7cnão verificadovulncheckvulncheck.com/xdb/7b5f88d13907não verificadovulncheckvulncheck.com/xdb/d0682c028430não verificadovulncheckvulncheck.com/xdb/3346a89083f0não verificadovulncheckvulncheck.com/xdb/f459dd355b00não verificadovulncheckvulncheck.com/xdb/30044911c5a5não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.