A security flaw has been discovered in the JCE editor extension used by many Joomla content management system websites. The issue lets people who do not have authorized login access to your site create new editor profiles for your Joomla installation. If attackers exploit this flaw, they can use those unauthorized profiles to upload and run harmful PHP code on your website. This could let them make unwanted changes to your site, steal sensitive visitor or business data, or take other unauthorized actions on your hosted Joomla site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907