CVE-2026-65889: Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
Affected Software
2 affected components
balbooa.com Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65889?
CVE-2026-65889 has a critical severity rating of 9.2.
2
How do I fix CVE-2026-65889?
To fix CVE-2026-65889, update the Gridbox extension to version 2.20.2 or later.
3
What type of vulnerability is CVE-2026-65889?
CVE-2026-65889 is classified as a Path Traversal vulnerability.
4
What can attackers do with CVE-2026-65889?
Attackers can perform unauthenticated recursive directory deletions through the affected method.
5
Which software is affected by CVE-2026-65889?
CVE-2026-65889 affects the balbooa.com Gridbox extension versions prior to 2.20.2.