Executive brief
Gridbox is a popular drag-and-drop page builder used to design and manage Joomla websites. A security flaw in versions prior to 2.20.2 allows unauthorized individuals to view sensitive files on the website's server without needing a password. This could lead to the exposure of configuration details or other private data, potentially aiding further attacks against the site.
Technical details
The Gridbox extension for Joomla (com_gridbox) contains multiple unauthenticated file system disclosure vulnerabilities in versions prior to 2.20.2. The flaw stems from insufficient input validation on certain endpoints, allowing a remote, unauthenticated attacker to bypass directory restrictions and read files from the server's file system. This was part of a larger set of 23 vulnerabilities discovered during a security audit of the component. Attackers can exploit this by sending specially crafted HTTP requests to the vulnerable component. Users should update to Gridbox version 2.20.2 or later to remediate these issues.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-20: patched: Initial partial fix in version 2.20.1
- 2026-07-29: advisory: Full disclosure of 23 vulnerabilities including this one
- 2026-07-29: disclosed: CVE-2026-66489 published