CVE-2026-65885: Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
Affected Software
2 affected components
balbooa.com/Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
DescriptionWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65885?
CVE-2026-65885 has a critical severity rating of 9.4.
2
How do I fix CVE-2026-65885?
To fix CVE-2026-65885, update the Gridbox extension to version 2.20.2 or later.
3
What type of vulnerability is CVE-2026-65885?
CVE-2026-65885 is an authenticated arbitrary file upload vulnerability.
4
What software is affected by CVE-2026-65885?
CVE-2026-65885 affects the Gridbox extension from balbooa.com.
5
What can be exploited due to CVE-2026-65885?
Authenticated attackers can exploit CVE-2026-65885 to upload arbitrary files, potentially leading to remote code execution.