Junglewise Threat Intelligence

CVE-2026-65889: Balbooa Gridbox for Joomla unauthenticated recursive directory deletion

CVE-2026-65889 · Severity: info · CVSS 9.2 · Published 2026-07-29

Technologies: Balbooa Gridbox. Vendors: Balbooa.

Executive brief

The Gridbox extension for Joomla, a popular drag-and-drop page builder, contains a vulnerability that allows unauthenticated users to delete directories on the server. An attacker can exploit this to cause significant data loss or take the website offline by deleting critical system or application folders. This issue is part of a larger set of critical vulnerabilities affecting the product that could lead to complete site compromise.

Technical details

A vulnerability in the 'generateNewApp' method of the Balbooa Gridbox extension (com_gridbox) for Joomla allows for unauthenticated recursive directory deletion. The flaw stems from improper access control (CWE-284) and path traversal (CWE-22) vulnerabilities, where the application fails to validate user-supplied input before performing file system operations. A remote, unauthenticated attacker can send a specially crafted HTTP request to trigger the deletion of arbitrary directories reachable by the web server process. This can lead to a permanent Denial of Service (DoS) or loss of application data. The issue is resolved in version 2.20.2.

Affected products

  • balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1

Timeline

  • 2026-07-20: patched: Initial partial fix in version 2.20.1
  • 2026-07-29: advisory: Full disclosure of 23 vulnerabilities including this one
  • 2026-07-29: disclosed: CVE-2026-65889 published

References

Related threats