CVE-2026-65887
Received Received - Intake

Unauthenticated Password Reset in Gridbox Joomla Extension

Vulnerability report for CVE-2026-65887, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-30

Assigner: Joomla! Project

Description

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-30
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
balbooa gridbox to 2.20.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated arbitrary password reset in the Joomla extension Gridbox versions before 2.20.2. It allows attackers to reset any user's password without authentication, enabling them to log in and impersonate those users, except for super administrators.

Detection Guidance

Check if Gridbox versions prior to 2.20.2 are installed. Inspect Joomla user password reset logs for unauthorized password change attempts targeting non-super admin accounts.

Impact Analysis

Attackers can gain unauthorized access to user accounts, leading to data theft, account manipulation, or further compromise of the system. Since it affects all users except super admins, it poses a significant risk to user data and system integrity.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties and reputational damage due to non-compliance.

Mitigation Strategies

Update Gridbox to version 2.20.2 or later immediately. Temporarily disable password reset functionality if an update is not immediately possible. Review user accounts for unauthorized changes and revoke suspicious sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65887. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart