Unauthenticated Password Reset Vulnerability in Gridbox by Balbooa
CVE-2026-65887
10CRITICAL
What is CVE-2026-65887?
The Gridbox extension for Joomla by Balbooa has a vulnerability that allows any actor to execute an unauthenticated password reset. This flaw permits unauthorized users to reset the passwords of any registered user except super admins, effectively granting them access to the accounts of those users. This poses a significant security risk as it can lead to unauthorized actions taken on behalf of these users.
Affected Version(s)
Gridbox extension for Joomla 1.0.0-2.20.1
