What is CVE-2026-65891?
CVE-2026-65891 is a vulnerability in the Joomla Content Editor (JCE) extension. Due to improper input validation in the file rename functionality, an authenticated user with file management permissions can overwrite unintended files and create hidden files in versions prior to 2.20.2. It is recommended to update JCE to the latest version.
Azərbaycanca: CVE-2026-65891, Joomla Content Editor (JCE) əlavəsində aşkarlanan boşluqdur. JCE 2.20.2 versiyasından əvvəlki versiyalarda fayl adının dəyişdirilməsi funksiyasında düzgün olmayan giriş yoxlaması səbəbilə fayl idarəetmə icazələrinə malik autentifikasiya olunmuş istifadəçi başqa faylların üzərinə yaza bilər. JCE-ni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What permissions must an attacker have to exploit CVE-2026-65891?
The attacker must be an authenticated user with file management permissions in the JCE extension.
How can the CVE-2026-65891 vulnerability be mitigated?
It is recommended to update the JCE extension to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.