Account Takeover Vulnerability in Balbooa Gridbox Extension
CVE-2026-65888
10CRITICAL
What is CVE-2026-65888?
The Balbooa Gridbox extension for Joomla is affected by a vulnerability that allows unauthorized users to log in as any registered user on the site through the socialLogin method. Versions prior to 2.20.2 do not properly validate user identities, leading to potential account takeover. It's essential for users to update their extensions to ensure robust security against unauthorized access.
Affected Version(s)
Gridbox extension for Joomla 1.0.0-2.20.1
