CVE-2026-61425: Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
Published Jul 20, 2026
·Updated
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
Affected Software
1 affected component
balbooa.com/Gridbox<1.6.0
Event History
Jul 20, 2026
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61425?
CVE-2026-61425 has a critical severity rating of 9.4 on the CVSS scale.
2
How do I fix CVE-2026-61425?
To fix CVE-2026-61425, update the Gridbox extension to version 1.6.0 or higher.
3
What type of vulnerability is CVE-2026-61425?
CVE-2026-61425 is an authentication bypass vulnerability in the Gridbox Joomla extension.
4
What are the potential impacts of CVE-2026-61425?
CVE-2026-61425 can lead to unauthorized admin access, compromising the security of affected Joomla sites.
5
Which software is affected by CVE-2026-61425?
CVE-2026-61425 affects the Gridbox extension developed by balbooa.com, specifically versions prior to 1.6.0.