CVE-2026-61425
Received Received - Intake

Authenticated Admin Bypass in Gridbox Joomla Extension

Vulnerability report for CVE-2026-61425, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: Joomla! Project

Description

The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
balbooa gridbox 2.20.1
balbooa gridbox From 2.20.1 (exc)
balbooa gridbox From 2.20.0.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Joomla extension Gridbox has an authentication bypass vulnerability that allows attackers to gain full admin access by setting a single browser cookie with an administrator's username. This bypasses all authentication requirements like passwords or login forms, effectively compromising the entire site.

Detection Guidance

Check if Gridbox version is below 2.20.1 by inspecting the extension in Joomla admin panel or via file system. Look for unauthorized Super User accounts or modified template files. Use Joomla's user management to review administrator accounts and recent logins.

Impact Analysis

This vulnerability allows attackers to gain Super User access to a Joomla site, enabling them to edit PHP template files and potentially take over the server. All prior versions of Gridbox are affected, and no configuration changes can mitigate this issue.

Compliance Impact

This vulnerability allows attackers to gain full administrative access to Joomla sites by bypassing authentication, which could lead to unauthorized data access, modification, or deletion. For GDPR, this could result in unauthorized processing of personal data, breaches of data integrity, and failure to maintain appropriate security measures. Under HIPAA, it may expose protected health information to unauthorized parties, violating confidentiality and integrity requirements.

Mitigation Strategies

Update Gridbox to version 2.20.1 or later immediately. Remove any suspicious Super User accounts and check for unauthorized changes to template files. Monitor administrator logins for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61425. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart