Junglewise Threat Intelligence

CVE-2026-65887: Balbooa Gridbox unauthenticated arbitrary password reset

CVE-2026-65887 · Severity: info · CVSS 10 · Published 2026-07-29

Technologies: Balbooa Gridbox. Vendors: Balbooa.

Executive brief

Balbooa Gridbox, a popular page builder for Joomla websites, contains a critical security flaw that allows anyone to reset the password of any user account except for super administrators. By exploiting this vulnerability, an unauthorized person could gain access to user accounts, potentially leading to the theft of customer data or unauthorized changes to the website's content. This issue is part of a larger set of vulnerabilities that are currently being exploited in the wild, making immediate updates essential to protect business operations and reputation.

Technical details

An improper access control vulnerability (CWE-284) exists in the 'resetPassword' method of the Balbooa Gridbox extension for Joomla. The flaw allows an unauthenticated remote attacker to reset the password for any user account, with the exception of super administrators. This is achieved by directly invoking the method without proper session or token validation. Once the password is reset, the attacker can log in as the target user. This vulnerability is part of a suite of 23 critical flaws discovered in the component, some of which are reportedly being exploited in the wild. Users should update to version 2.20.2 immediately to remediate this and other associated risks.

Affected products

  • balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1

Timeline

  • 2026-07-20: patched: Initial fix in 2.20.1 (incomplete)
  • 2026-07-29: advisory: Full disclosure of 23 vulnerabilities including this one
  • 2026-07-29: patched: Final fix released in version 2.20.2
  • 2026-07-29: exploited: Reported as being exploited in the wild at time of disclosure

References

Related threats