Unauthenticated Recursive Directory Deletion in Balbooa Gridbox by Joomla
CVE-2026-65889
9.2CRITICAL
What is CVE-2026-65889?
The Balbooa Gridbox extension for Joomla has a vulnerability that allows unauthenticated users to execute recursive directory deletion through the 'generateNewApp' method. This flaw, present in versions prior to 2.20.2, exposes sensitive files and directories to removal, potentially compromising the integrity of the website and its data.
Affected Version(s)
Gridbox extension for Joomla 1.0.0-2.20.1
