CVE-2026-65884: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
Affected Software
2 affected components
Joomla Extension (balbooa.com) - Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·12:09 PM
Data Sourced
via MITRE·12:09 PM
DescriptionWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65884?
CVE-2026-65884 has a critical severity rating of 10 on the CVSS scale.
2
How do I fix CVE-2026-65884?
To fix CVE-2026-65884, upgrade your Joomla Gridbox extension to version 2.20.2 or later.
3
What type of vulnerability is CVE-2026-65884?
CVE-2026-65884 is a privilege escalation vulnerability that allows unauthorized users to gain administrative permissions.
4
Who is affected by CVE-2026-65884?
Users of the Gridbox extension version prior to 2.20.2 are affected by CVE-2026-65884.
5
When was CVE-2026-65884 published?
CVE-2026-65884 was published on July 29, 2026.