Executive brief
Gridbox, a popular drag-and-drop website builder for the Joomla content management system, contains a critical security flaw in its social login functionality. This vulnerability allows an attacker to bypass security checks and log in as any user on the website, including administrators, without needing a password. An attacker who successfully exploits this can take full control of the website, potentially leading to data theft, site defacement, or the installation of malicious software.
Technical details
An improper access control vulnerability (CWE-284) exists in the 'socialLogin' method of the Balbooa Gridbox extension for Joomla. The flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms and log in as any existing user on the target site by providing specific parameters to the vulnerable method. This is part of a larger set of 23 vulnerabilities discovered in the component, including remote code execution and SQL injection. The vulnerability is being actively exploited in the wild. Users should update to Gridbox version 2.20.2 or later to remediate this and other critical flaws.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-20: patched: Initial partial fix in version 2.20.1
- 2026-07-29: disclosed: Full disclosure of 23 vulnerabilities including CVE-2026-65888
- 2026-07-29: advisory
- 2026-07-29: exploited: Confirmed active exploitation in the wild by Joomla Security Strike Team