SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-65886

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Joomla Extension from balbooa.com, specifically Gridbox versions prior to 2.20.2, is vulnerable to unauthenticated arbitrary file reading, enabling attackers to access sensitive files on the server. This exposure could lead to data leakage or further exploitation of the system. Joomla administrators and users of the Gridbox extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-65886
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

Related CVEs

Other vulnerabilities affecting the same vendor(s)