Path Traversal Vulnerability in Gridbox by Balbooa
CVE-2026-102783

6.3MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-102783?

The Gridbox extension by Balbooa contains a path traversal vulnerability that allows an attacker to manipulate the file paths used in the image preview feature. Specifically, the showImage action resolves a request-controlled path and can unintentionally reference files from sibling directories, such as images-backup, circumventing the intended restrictions. This behavior occurs when image decoding fails or is unavailable, enabling unauthorized access to sensitive images outside the configured media root. While the extension limits file access through specific image types, the potential for exploitation exists, highlighting a security concern that requires attention.

Affected Version(s)

Gridbox extension for Joomla 1.0.0-2.20.3.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergiy Tryzhychynskyi
.