A security vulnerability (identified as CVE-2026-48907) affects the JCE editor extension used on Joomla-based websites. This flaw allows people who do not have valid login credentials for your site to create new, unauthorized editor user profiles for the extension.
Once an attacker creates one of these unapproved profiles, they can upload and run PHP code on your website. This could let them take full control of your site, steal personal information from your visitors, deface your public pages, or use your site to spread spam and malware to other internet users.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907