CVE-2026-65887: Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
Affected Software
2 affected components
balbooa.com/Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65887?
CVE-2026-65887 has a critical severity rating of 10.
2
How do I fix CVE-2026-65887?
To fix CVE-2026-65887, update Gridbox to version 2.20.2 or higher.
3
What does CVE-2026-65887 allow an attacker to do?
CVE-2026-65887 allows an attacker to perform an unauthenticated arbitrary password reset and log in as any user excluding super admins.
4
Which software is affected by CVE-2026-65887?
CVE-2026-65887 affects the Joomla Extension Gridbox from balbooa.com.
5
When was CVE-2026-65887 published?
CVE-2026-65887 was published on July 29, 2026.