A security flaw has been identified in the JCE editor add-on for Joomla content management systems. This issue allows people who do not have login access to your Joomla site to create new editor profiles on the platform. Those unauthorized profiles can then be used to upload and run custom PHP code (the type of code that powers dynamic features on your website) directly on your web server.
If this flaw is exploited, attackers could alter your site’s content, access sensitive information stored on your site, take control of site functions, or even use your compromised site to harm visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907