SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65884

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Gridbox extension for Joomla versions prior to 2.20.2 is vulnerable to a privilege escalation flaw that permits unauthenticated users to register accounts with administrative permissions by specifying usergroup IDs. This could lead to unauthorized access and control over the Joomla site, making it critical for Joomla administrators and users of the Gridbox extension to prioritize patching this vulnerability. Immediate action is recommended to mitigate the risk of exploitation.

CVE
CVE-2026-65884
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)