Description
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
Published: 2026-07-29
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gridbox extension for Joomla allows the registration method to accept arbitrary usergroup IDs, permitting an unauthenticated actor to create a new account with administrative permissions. This flaw enables a privilege escalation attack that can give the attacker full control over the Joomla site. The vulnerability is categorized as a CWE-284 deficiency in access control and is also listed by NVD as NVD-CWE-noinfo, indicating an associated unclassified weakness.

Affected Systems

The flaw affects the Gridbox extension from balbooa.com when its version is older than 2.20.2. Users running any release below this version are susceptible.

Risk and Exploitability

With a CVSS score of 10 the flaw is considered critical. The EPSS score of less than 1% indicates that, while exploitation is not yet widespread, the flaw is trivially reachable through the public registration endpoint and requires no special access; any user can submit a registration request with an elevated usergroup ID. The vulnerability is not currently listed in the CISA KEV catalog, but the potential for a complete takeover of the site makes it a high priority for remediation.

Generated by OpenCVE AI on August 12, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gridbox extension to version 2.20.2 or later, which removes the ability to specify arbitrary usergroup IDs during registration.
  • Disable or tightly restrict the public registration functionality so that only authorized users can create new accounts, and ensure that administrative roles cannot be assigned through the registration form.
  • Audit the current user base for accounts that were created before the patch and possess administrative privileges, and revoke or re‑assign any that appear anomalous or unnecessary.

Generated by OpenCVE AI on August 12, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
References

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Wed, 29 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
Title Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Balbooa Gridbox
Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:56:01.778Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65884

cve-icon Vulnrichment

Updated: 2026-07-29T12:40:14.315Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T13:19:10.677

Modified: 2026-08-05T18:37:44.247

Link: CVE-2026-65884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T11:15:03Z

Weaknesses