CVE-2026-65888
balbooa.com · Gridbox extension for Joomla
The Gridbox extension for Joomla is affected by an account takeover vulnerability via the socialLogin method, allowing unauthenticated attackers to impersonate any user.
Executive summary
A critical account takeover vulnerability in the balbooa.com Gridbox extension for Joomla allows unauthenticated attackers to impersonate arbitrary users.
Vulnerability
This is an improper access control flaw (CWE-284) within the socialLogin method. The function fails to properly verify the identity of the user, allowing unauthenticated actors to log in as any user registered on the target site.
Business impact
This vulnerability provides a direct pathway for attackers to gain full access to any user account, including those with elevated privileges. The impact includes the total loss of confidentiality and integrity for the affected user accounts and the potential for lateral movement within the application. The CVSS score of 10.0 underscores the severe risk posed to the security of the Joomla environment.
Remediation
Immediate Action: Update the balbooa.com Gridbox extension for Joomla to version 2.20.2 or later.
Proactive Monitoring: Review logs for unauthorized logins occurring via the social login feature, particularly those involving high-privilege accounts.
Compensating Controls: If patching is delayed, disable the social login functionality within the Gridbox extension to prevent exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations must prioritize updating to the latest version of the Gridbox extension to close this authentication bypass vector. Given the severity of an account takeover, administrators should verify that no unauthorized accounts have been accessed or created during the period the site remained vulnerable.