Joomla CVE-2026-48907 and CVE-2026-48908: Unauthenticated Upload in Two Extensions
Two Joomla extensions carry unauthenticated arbitrary file upload vulnerabilities: CVE-2026-48907 in JCE Editor and CVE-2026-48908 in SP Page Builder. FortiGuard Labs continued to observe active exploitation of CVE-2026-48908 after public disclosure. Both are rated high, and either one ends the same way, with attacker-controlled PHP on the web server.
The defect
The affected endpoints include profiles.import in JCE Editor and asset.uploadCustomIcon in SP Page Builder. Those endpoints accept a file without verifying the caller's identity and without validating the file type or content. No credential and no session are required, which is what makes the flaw unauthenticated rather than a privilege escalation. Uploading a file that executes as PHP then produces remote code execution on the server hosting the CMS.
The pattern is not exotic. A component that performs an administrative operation, such as importing a profile or setting an icon, is reachable through a route that does not check the administrative context. The consequence is direct: what should have been an editor feature becomes an anonymous write primitive.
Why extension flaws dominate Joomla incidents
Joomla's core has a small attack surface compared with its extension catalogue. Sites accumulate page builders, editors, form components and template frameworks because they are what makes the CMS usable, and each becomes a separately versioned dependency that the site owner must track. A site can be fully patched at the core and still expose a vulnerable extension, so an attacker does not need a sophisticated chain when a single endpoint accepts a file.
Detection and response
- Check the installed versions of JCE Editor and SP Page Builder, and update them to the releases that fix these identifiers.
- Review the web server access log for POST requests to
profiles.importandasset.uploadCustomIcon, and treat external source addresses as suspicious regardless of response code. - Look for newly created PHP files in upload, media, cache and template directories, and compare against a known-good file listing.
- Inspect user tables and extension tables for accounts or components created outside the change process.
- If a web shell is found, treat credentials reachable from that host as exposed and rotate them after removal.
References
- FortiGuard outbreak alerts, including the SP Page Builder RCE entry: https://www.fortiguard.com/outbreak-alert
- Joomla security centre: https://developer.joomla.org/security-centre.html
- NVD record for CVE-2026-48908: https://nvd.nist.gov/vuln/detail/CVE-2026-48908
- NVD record for CVE-2026-48907: https://nvd.nist.gov/vuln/detail/CVE-2026-48907
Top comments (0)