A security flaw has been identified in the JCE Editor extension, a common add-on for the Joomla website building platform. This issue allows people who do not have login access to your site (unauthenticated users) to create new, unauthorized editor profiles on your Joomla installation without permission.
Once these fake profiles are set up, attackers can upload and run custom PHP code on your web server. This level of access could let bad actors steal visitor data, alter your site’s content or design, or use your hosting resources for harmful activities.
If you operate a Joomla site with the JCE Editor extension installed, this vulnerability impacts your setup.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907