← Back to browse · API

CVE-2026-65887

Severity
CRITICAL
CVSS
10.0
EPSS
0.00284
Risk score
40.1
CISA KEV
No
PoC
No
Published
2026-07-29
Modified
2026-08-12
First seen
2026-08-05
Aliases
EUVD-2026-50355, GHSA-F53F-94JH-JCHQ
Products
balbooa.com:Gridbox extension for Joomla 1.0.0-2.20.1, balbooa:gridbox
Sources
euvd EUVD-2026-50355
nvd CVE-2026-65887

Description

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

References