Junglewise Threat Intelligence

CVE-2026-65884: Balbooa Gridbox privilege escalation in registration method

CVE-2026-65884 · Severity: info · CVSS 10 · Published 2026-07-29

Technologies: Balbooa Gridbox. Vendors: Balbooa.

Executive brief

Balbooa Gridbox, a popular website builder extension for the Joomla content management system, contains a critical security flaw in its user registration process. This vulnerability allows anyone on the internet to register a new account and assign themselves administrative privileges. An attacker could use this to take full control of the website, access sensitive customer data, or take the site offline.

Technical details

A privilege escalation vulnerability exists in Balbooa Gridbox versions prior to 2.20.2. The registration method fails to properly validate or restrict the usergroup IDs provided in registration requests. An unauthenticated remote attacker can exploit this by submitting a crafted registration request that includes an administrative usergroup ID, resulting in the creation of a new account with full administrative permissions. This is a failure of improper access control (CWE-284). The issue is resolved in version 2.20.2.

Affected products

  • balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched: Fixed in version 2.20.2

References

Related threats