Unauthenticated Password Reset Vulnerability in Gridbox by Balbooa
CVE-2026-65887

10CRITICAL

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-65887?

The Gridbox extension for Joomla by Balbooa has a vulnerability that allows any actor to execute an unauthenticated password reset. This flaw permits unauthorized users to reset the passwords of any registered user except super admins, effectively granting them access to the accounts of those users. This poses a significant security risk as it can lead to unauthorized actions taken on behalf of these users.

Affected Version(s)

Gridbox extension for Joomla 1.0.0-2.20.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.