Description
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
Published: 2026-07-29
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to request the photo viewer route within the Gridbox Joomla extension and retrieve the contents of arbitrary files stored on the web server. This is a path traversal flaw (CWE-22) that can expose sensitive configuration files, user credentials, or other confidential data, potentially leading to information disclosure.

Affected Systems

Gridbox extension for Joomla from balbooa.com, versions prior to 2.20.2, is affected. Any installation of this extension that has not been upgraded to 2.20.2 or later is vulnerable.

Risk and Exploitability

The CVSS score of 9.2 highlights a severe confidentiality risk. The EPSS value of less than 1% indicates that current exploitation likelihood is minimal, and the issue is not listed in CISA’s KEV. The likely attack vector is sending web requests to the photo viewer endpoint without authentication, allowing an attacker to read arbitrary files from any network location.

Generated by OpenCVE AI on August 4, 2026 at 12:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gridbox extension to version 2.20.2 or newer to remove the path traversal vulnerability (CWE-22).
  • Restrict or disable the photo viewer functionality for unauthenticated users to mitigate the CWE-22 flaw.
  • Implement web application firewall or network-level rules that block unauthorized file‑read attempts, preventing exploitation of the CWE‑22 path traversal.

Generated by OpenCVE AI on August 4, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Wed, 29 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
Title Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Balbooa Gridbox
Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:56:27.746Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65886

cve-icon Vulnrichment

Updated: 2026-07-29T16:43:05.549Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T15:16:28.467

Modified: 2026-08-05T17:24:10.843

Link: CVE-2026-65886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:30:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')