DEV Community

jeffrey
jeffrey

Posted on

Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions

Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions

Two Joomla extensions carry unauthenticated arbitrary file upload vulnerabilities: CVE-2026-48907 in JCE Editor and CVE-2026-48908 in SP Page Builder. FortiGuard Labs continued to observe active exploitation of CVE-2026-48908 after public disclosure. Both are rated high, and either one ends the same way, with attacker-controlled PHP on the web server.

The defect

The affected endpoints include profiles.import in JCE Editor and asset.uploadCustomIcon in SP Page Builder. Those endpoints accept a file without verifying the caller's identity and without validating the file type or content. No credential and no session are required, which is what makes the flaw unauthenticated rather than a privilege escalation. Uploading a file that executes as PHP then produces remote code execution on the server hosting the CMS.
The pattern is not exotic. A component that performs an administrative operation, such as importing a profile or setting an icon, is reachable through a route that does not check the administrative context. The consequence is direct: what should have been an editor feature becomes an anonymous write primitive.

Why extension flaws dominate Joomla incidents

Joomla's core has a small attack surface compared with its extension catalogue. Sites accumulate page builders, editors, form components and template frameworks because they are what makes the CMS usable, and each becomes a separately versioned dependency that the site owner must track. A site can be fully patched at the core and still expose a vulnerable extension, so an attacker does not need a sophisticated chain when a single endpoint accepts a file.

Detection and response

  • Check the installed versions of JCE Editor and SP Page Builder, and update them to the releases that fix these identifiers.
  • Review the web server access log for POST requests to profiles.import and asset.uploadCustomIcon, and treat external source addresses as suspicious regardless of response code.
  • Look for newly created PHP files in upload, media, cache and template directories, and compare against a known-good file listing.
  • Inspect user tables and extension tables for accounts or components created outside the change process.
  • If a web shell is found, treat credentials reachable from that host as exposed and rotate them after removal.

References

Top comments (0)