Description
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
Published: 2026-07-29
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gridbox extension for Joomla contains a flaw in its socialLogin method that enables an attacker to authenticate as any user on the site, bypassing the normal login process and granting full access to that account. This improper authorization vulnerability, identified as an authorization issue (CWE-284), allows an attacker to assume the privileges of the compromised user, exposing the confidentiality, integrity, and availability of the affected accounts and site operations.

Affected Systems

The balbooa.com Gridbox extension for Joomla is vulnerable when its version is lower than 2.20.2. All installed instances below that version boundary are susceptible; no other version ranges are specified, so any pre‑2.20.2 release should be treated as affected.

Risk and Exploitability

The CVSS score of 10 highlights the critical nature of this flaw, while the EPSS score of less than 1% indicates rare exploitation at present. The socialLogin method is exposed via the public login interface; the likely attack vector is remote over the network. Although the flaw is not listed in the CISA KEV catalog, the high severity and potential for remote abuse warrant immediate attention.

Generated by OpenCVE AI on August 12, 2026 at 11:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gridbox extension to version 2.20.2 or later, which includes a fix for the socialLogin authorization issue.
  • If an upgrade cannot be performed immediately, disable or remove the socialLogin feature within the Gridbox configuration or by code modification to block exploitation.
  • Enforce strong password policies and enable multi‑factor authentication for all user accounts to reduce the impact if credentials are compromised.

Generated by OpenCVE AI on August 12, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Wed, 29 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
Title Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Balbooa Gridbox
Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:57:39.892Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65888

cve-icon Vulnrichment

Updated: 2026-07-31T16:12:23.470Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T15:16:28.813

Modified: 2026-08-05T17:23:55.893

Link: CVE-2026-65888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T11:30:03Z

Weaknesses