SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-65888

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Gridbox extension for Joomla versions prior to 2.20.2 is vulnerable to an account takeover due to a flaw in the socialLogin method, which permits unauthorized actors to log in as any user on the affected site. This vulnerability poses a significant risk to website integrity and user data security. Joomla site administrators using this extension should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-65888
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%

Original NVD Description

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

Related CVEs

Other vulnerabilities affecting the same vendor(s)