CVE-2026-65888: Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
Affected Software
2 affected components
balbooa.com/Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65888?
The severity of CVE-2026-65888 is rated as critical with a CVSS score of 10.
2
How do I fix CVE-2026-65888?
To fix CVE-2026-65888, you should update the Gridbox extension to version 2.20.2 or later.
3
What type of vulnerability is CVE-2026-65888?
CVE-2026-65888 is an account takeover vulnerability affecting the Gridbox Joomla extension.
4
What are the implications of CVE-2026-65888?
The implications of CVE-2026-65888 include unauthorized access to user accounts on affected sites.
5
Who is affected by CVE-2026-65888?
Anyone using versions of the Gridbox Joomla extension earlier than 2.20.2 is potentially affected by CVE-2026-65888.