SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65889

HIGH · CVSS 7.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Joomla Extension from balbooa.com prior to version 2.20.2 is vulnerable to unauthenticated recursive directory deletion through the generateNewApp method, allowing attackers to delete directories without authentication. This vulnerability poses a significant risk to web applications using the affected extension, potentially leading to data loss and service disruption. Web administrators and developers utilizing this extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-65889
Severity
HIGH
CVSS
7.5
EPSS
0.29%

Original NVD Description

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

Related CVEs

Other vulnerabilities affecting the same vendor(s)