Description
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
Published: 2026-07-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Gridbox is vulnerable to an authentication bypass, potentially leading to full admin access. This flaw allows an attacker to circumvent standard authentication mechanisms and gain unrestricted administrative privileges, as described in the updated vulnerability description. The issue is categorized as CWE‑288 and carries a CVSS score of 9.4, indicating a severe risk to confidentiality, integrity, and availability.

Affected Systems

All installations of the Balbooa.com Gridbox Joomla extension using version 1.5.x or older are affected. The flaw applies regardless of the Joomla core version, impacting every site that has not upgraded to the patched 1.6.0 release.

Risk and Exploitability

The high CVSS rating indicates a critical risk level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, implying no widespread public exploits at this time. Attackers can exploit the flaw by manipulating authentication flows or logging in with arbitrary credentials to gain full admin control over the site. Given the severity and potential impact on site integrity and confidentiality, immediate remedial action is strongly recommended.

Generated by OpenCVE AI on August 3, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy Gridbox 1.6.0 or newer to eliminate the authentication bypass.
  • If an upgrade cannot be performed immediately, uninstall or disable the Gridbox extension to block exploitation.
  • Monitor Joomla administration logs for unauthorized activity.

Generated by OpenCVE AI on August 3, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
Title Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T15:01:22.667Z

Reserved: 2026-07-09T13:39:11.897Z

Link: CVE-2026-61425

cve-icon Vulnrichment

Updated: 2026-07-21T12:36:03.958Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:15:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel