CVE-2026-65886: Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
Affected Software
2 affected components
balbooa.com/Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65886?
The severity of CVE-2026-65886 is rated as critical with a CVSS score of 9.2.
2
How do I fix CVE-2026-65886?
To fix CVE-2026-65886, update the Gridbox extension to version 2.20.2 or later.
3
What type of vulnerability is CVE-2026-65886?
CVE-2026-65886 is a path traversal vulnerability allowing unauthenticated file reading.
4
Who is affected by CVE-2026-65886?
Anyone using Gridbox versions prior to 2.20.2 is affected by CVE-2026-65886.
5
What can attackers do with CVE-2026-65886?
Attackers can view arbitrary files on the server due to the unauthenticated access.