Description
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
Published: 2026-07-29
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows authenticated users to upload arbitrary files through the Gridbox extension for Joomla. The upload process does not properly validate file types, causing the possibility of executing malicious code when combined with the related CVE-2026-65884; it is classified as CWE-434.

Affected Systems

The Gridbox extension from balbooa.com for Joomla is affected in versions earlier than 2.20.2. Sites that have installed these versions and grant upload permissions to administrators or editors are vulnerable.

Risk and Exploitability

The CVSS score of 9.4 signifies critical severity, and the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. Because the flaw requires authenticated access, an attacker who can create an account or compromise an existing one can upload malicious files, potentially leading to remote code execution. The vulnerability is not listed in CISA KEV, but its impact warrants immediate action.

Generated by OpenCVE AI on August 3, 2026 at 13:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gridbox extension to version 2.20.2 or later.
  • Restrict file uploads to non‑executable types and remove any plugin that allows arbitrary file uploads.
  • Audit and enforce least‑privilege on Joomla administrator accounts, disabling upload permissions for users without editorial rights.

Generated by OpenCVE AI on August 3, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
References

Wed, 29 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
Title Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Balbooa Gridbox
Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:52:19.632Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65885

cve-icon Vulnrichment

Updated: 2026-07-29T12:41:12.708Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T13:19:10.820

Modified: 2026-08-05T18:37:52.050

Link: CVE-2026-65885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:30:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type