CVE-2026-65887: CWE-284 Improper Access Control in balbooa.com Gridbox extension for Joomla
A critical vulnerability (CVE-2026-65887) exists in the balbooa.com Gridbox extension for Joomla versions 1.0.0 through 2.20.1. This vulnerability allows unauthenticated attackers to arbitrarily reset passwords of any user except super administrators via the resetPassword method. Successful exploitation enables attackers to log in and act as those users. The vulnerability is classified as improper access control (CWE-284) and has a CVSS 4.0 base score of 10. No official patch or remediation guidance is currently provided by the vendor.
AI Analysis
Technical Summary
CVE-2026-65887 is an improper access control vulnerability in the balbooa.com Gridbox extension for Joomla, affecting versions 1.0.0 through 2.20.1. The flaw resides in the resetPassword method, which permits unauthenticated actors to reset passwords for any user account except super administrators. This allows attackers to gain unauthorized access and perform actions as those users. The vulnerability has a critical severity with a CVSS 4.0 score of 10, indicating network exploitable, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. No official fix or patch is currently documented.
Potential Impact
Exploitation of this vulnerability allows unauthenticated attackers to reset passwords of any user except super administrators, leading to unauthorized access and potential full compromise of affected user accounts. This can result in data exposure, unauthorized actions, and potential disruption of services associated with those accounts. The vulnerability does not affect super administrator accounts, limiting the highest privilege compromise but still poses a critical risk to other user accounts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the Gridbox extension and monitor for suspicious activity. Consider disabling or limiting the use of the resetPassword functionality if possible. Follow updates from balbooa.com and Joomla for any forthcoming patches or official mitigations.
CVE-2026-65887: CWE-284 Improper Access Control in balbooa.com Gridbox extension for Joomla
Description
A critical vulnerability (CVE-2026-65887) exists in the balbooa.com Gridbox extension for Joomla versions 1.0.0 through 2.20.1. This vulnerability allows unauthenticated attackers to arbitrarily reset passwords of any user except super administrators via the resetPassword method. Successful exploitation enables attackers to log in and act as those users. The vulnerability is classified as improper access control (CWE-284) and has a CVSS 4.0 base score of 10. No official patch or remediation guidance is currently provided by the vendor.
CVSS v4.0
Score 10.0critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65887 is an improper access control vulnerability in the balbooa.com Gridbox extension for Joomla, affecting versions 1.0.0 through 2.20.1. The flaw resides in the resetPassword method, which permits unauthenticated actors to reset passwords for any user account except super administrators. This allows attackers to gain unauthorized access and perform actions as those users. The vulnerability has a critical severity with a CVSS 4.0 score of 10, indicating network exploitable, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. No official fix or patch is currently documented.
Potential Impact
Exploitation of this vulnerability allows unauthenticated attackers to reset passwords of any user except super administrators, leading to unauthorized access and potential full compromise of affected user accounts. This can result in data exposure, unauthorized actions, and potential disruption of services associated with those accounts. The vulnerability does not affect super administrator accounts, limiting the highest privilege compromise but still poses a critical risk to other user accounts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the Gridbox extension and monitor for suspicious activity. Consider disabling or limiting the use of the resetPassword functionality if possible. Follow updates from balbooa.com and Joomla for any forthcoming patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-07-23T09:17:01.409Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a13c09c2644c7f8a6d825
Added to database: 07/29/2026, 14:52:48 UTC
Last enriched: 07/29/2026, 15:08:00 UTC
Last updated: 07/29/2026, 15:28:24 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.