Description
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
Published: 2026-07-29
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gridbox Joomla extension contains a flaw in its resetPassword method that permits an unauthenticated actor to reset any user account’s password except super administrators. No authentication or authorization is required before changing credentials, enabling an attacker to assume the identity of any site user and use the user’s permissions to access sensitive data or perform further malicious actions.

Affected Systems

The vulnerable product is the Gridbox extension for Joomla, released by balbooa.com. Versions prior to 2.20.2 contain the flaw; versions 2.20.2 and later address it.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. The EPSS score of less than 1% suggests the vulnerability is not frequently exploited. It is not listed in the CISA KEV catalog. Attackers can easily exploit the flaw by calling the resetPassword endpoint with a valid or guessed user identifier, resetting the password, and then logging in as that user. No special conditions are required, making the risk high if the patch is not applied.

Generated by OpenCVE AI on August 12, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gridbox Joomla extension to version 2.20.2 or newer to remove the resetPassword flaw
  • If an upgrade cannot be performed immediately, restrict public access to the password reset endpoint to administrators or specific IP ranges
  • Disable the automatic password reset feature in the extension until a patch is available if the extension configuration allows it
  • Review audit logs for suspicious password reset activity and consider alerting on repeated reset attempts

Generated by OpenCVE AI on August 12, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Wed, 29 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
Title Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Balbooa Gridbox
Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:56:35.583Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65887

cve-icon Vulnrichment

Updated: 2026-07-31T16:12:36.340Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T15:16:28.613

Modified: 2026-08-05T17:24:03.673

Link: CVE-2026-65887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T11:15:03Z

Weaknesses