SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-65891

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Joomla Content Editor (JCE) versions prior to 2.20.2 are vulnerable due to improper input validation in the file rename functionality, which permits authenticated users with file management permissions to create hidden files and unintentionally overwrite existing files. This vulnerability could lead to unauthorized access to sensitive data or disruption of services. Joomla administrators and web developers using JCE should prioritize applying the latest updates to mitigate potential risks.

CVE
CVE-2026-65891
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.

Related CVEs

Other vulnerabilities affecting the same vendor(s)