Description
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
Published: 2026-07-29
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gridbox extension for Joomla is vulnerable to unauthenticated file system disclosure all versions prior to 2.20.2. An attacker can request arbitrary files from the server without needing valid credentials, revealing potentially sensitive or confidential data. The weakness aligns with CWE‑200, which denotes unauthorized disclosure of information. No additional exploitation paths that could compromise system integrity or availability are indicated in the description.

Affected Systems

The vulnerability affects the balbooa.com Gridbox extension for Joomla. All releases below version 2.20.2 are at risk. The affected platform is Joomla-based websites that have installed Gridbox extensions older than the listed version.

Risk and Exploitability

The CVSS score of 5.3 classifies this vulnerability as moderate. The EPSS score of less than 1% suggests a low probability of exploitation under normal conditions, and the vulnerability is not listed in the CISA KEV catalog. However, because the exploit requires no authentication, the potential impact could be significant if sensitive files (e.g., configuration files, developer keys, or backups) are exposed. The attack vector is inferred to be a remote attacker making HTTP requests to the Joomla site hosting Gridbox, as the description states the flaw is unauthenticated.

Generated by OpenCVE AI on August 2, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Gridbox extension version 2.20.2 or newer to remove the disclosure flaw
  • Configure file system permissions on the Joomla server to restrict read access to the web document root and configuration directories
  • Monitor web server logs for anomalous file access patterns that may indicate exploitation attempts

Generated by OpenCVE AI on August 2, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Wed, 29 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
Title Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
References

Subscriptions

Balbooa Gridbox
Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:53:58.325Z

Reserved: 2026-07-27T12:46:59.195Z

Link: CVE-2026-66489

cve-icon Vulnrichment

Updated: 2026-07-30T17:31:53.141Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T14:16:34.270

Modified: 2026-08-05T17:24:29.030

Link: CVE-2026-66489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor