LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 16, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 19, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-48907 to its Known Exploited Vulnerabilities catalog on Jun 16, 2026, with a federal patch deadline of Jun 19, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for…

This vulnerability affects the Widget Factory Joomla Content Editor and stems from improper access control. Unauthenticated users can create new editor profiles, which may permit upload and execution of PHP code on the server.

The issue matters for any organization running Joomla sites that use this editor component, as successful exploitation can lead to unauthorized code execution and potential full site compromise.

How it works

The weakness is categorized as CWE-284, improper access control. In this class of flaw, the application fails to enforce authentication or authorization checks on certain functions.

An attacker can abuse the missing controls by directly requesting the profile creation endpoint without credentials. Once a profile is created, the same path allows file uploads that the server may then execute as PHP.

Am I affected? How to find it in your systems

Inventory all Joomla installations and identify any that have the Widget Factory Content Editor extension installed. Check configuration files, the Joomla extensions database table, and file system paths under the components or plugins directories.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation step.

After patching, review and tighten access controls around editor profile management, restrict file upload types and destinations for the component, and ensure Joomla user permissions follow least-privilege principles.

If you can't patch immediately

Place the affected Joomla sites behind network segmentation that limits direct internet exposure to the administrative and editor endpoints.

If your data may have been exposed

Actively exploited access-control vulnerabilities in web applications have led to breaches involving unauthorized code execution. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWidget Factory · Joomla Content Editor
WeaknessCWE-284
Added to CISA KEVJun 16, 2026
Federal patch deadlineJun 19, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities