CVE-2026-48907: Unauthenticated RCE in the Joomla Content Editor extension
yeswehack.com | vulnerability | Critical | Actively exploited | CVE-2026-48907 | #active-exploitation | #rce | #public-poc | #access-control | #vulnerability | #patch-analysis | #webshell | #joomla | #cve-2026-48907
Summary
YesWeHack's analysis of CVE-2026-48907, a CVSS 10.0 unauthenticated RCE in the Joomla Content Editor: profile import abuse drops a PHP webshell; fixed in 2.9.99.5 with hardening in 2.9.99.6.
- CVSS
- 9.8
- Published
- Collected
Skip to content