SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-65887

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Gridbox extension for Joomla versions prior to 2.20.2 is vulnerable to an unauthenticated arbitrary password reset, enabling attackers to reset passwords for any user account, except for super admins. This flaw poses a significant risk as it allows unauthorized access to user accounts, potentially leading to data breaches or account takeovers. Joomla site administrators using the affected extension should prioritize applying the update to mitigate this security risk.

CVE
CVE-2026-65887
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%

Original NVD Description

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

Related CVEs

Other vulnerabilities affecting the same vendor(s)