← Vulnerability feed

Vulnerability record · CVE-2026-65887 · published 29 July 2026

CVE-2026-65887: Balbooa gridbox improper access control vulnerability

Balbooa · Gridbox

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

10.0 CVSS 4.0 Critical EPSS 0.52% · top 58.3% CWE-284 · Improper access control
10.0CVSS 4.0 base score
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
5 Aug 2026Last modified by NVD

Description

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-65887 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-65888Balbooa gridbox improper access control vulnerabilityJoomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…EPSS 0.52%10.0CVE-2026-65884Balbooa gridbox improper access control vulnerabilityJoomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…EPSS 0.52%9.4CVE-2026-65885Balbooa gridbox unrestricted file upload vulnerabilityJoomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo…EPSS 0.52%9.2CVE-2026-65886Balbooa gridbox path traversal vulnerabilityJoomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view …EPSS 0.55%9.2CVE-2026-65889Balbooa gridbox path traversal vulnerabilityJoomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…EPSS 0.44%9.2CVE-2026-65890Balbooa gridbox sql injection vulnerabilityJoomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…EPSS 0.50%7.3CVE-2026-65947Balbooa gridbox cross-site request forgery vulnerabilityJoomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2EPSS 0.19%6.1CVE-2026-66490Balbooa gridbox cross-site scripting vulnerabilityJoomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-65887), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.