2026-07-26HIGHexploitedThe Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super User, and Super User means PHP
Balbooa Gridbox for Joomla, password reset of any non-Super-User account (CVSS 4.0 10.0), exploit maturity Attacked; fixed in 2.20.2
cve · CVE-2026-65887
Coverage
1
first 2026-07-26 → last 2026-09-29
Latest activity
2026-09-29
The Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education · regions: europe
Sources cited
7
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-65887, newest first. Check the date before acting on an older one.
- Inventory Joomla sites for the Balbooa Gridbox page builder and update every one to 2.20.3.1, which also closes an unauthenticated blind SQL injection in the front-end blog author parameter present in every earlier build, 2.20.3 and 2.20.2.3 included. Anything below 2.20.2 is also exposed to the exploited follow-up batch, which 2.20.1 does not close, and the vulnerable code has shipped since the October 2025 release.2026-07-26CVE-2026-61425 +9
- On any site that ran Gridbox 2.20.1 or earlier while internet-reachable, review the Super User list and administrator-group members, remove accounts that entered an admin group through self-registration rather than an explicit administrative action, and review template files and the web root for changes, with particular attention to files written since 27 July.2026-07-26CVE-2026-61425 +9
Defender insights
What each entry about CVE-2026-65887 tells a defender to do, newest first.
Latest update · triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (3 across 2 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceCreate Account: Local Account · Server Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · ATT&CK page ↗
Persistence TA0003
T1136.001Create Account: Local Account×1
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · ATT&CK page ↗
Entries about Balbooa Gridbox for Joomla, password reset of any non-Super-User account (CVSS 4.0 10.0), exploit maturity Attacked; fixed in 2.20.2 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Balbooa Gridbox×1
- Balbooa Gridbox for Joomla×1
- Balbooa Gridbox for Joomla, authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2×1
- Balbooa Gridbox for Joomla, social-login method logs the caller in as any user (CVSS 4.0 10.0), exploit maturity Attacked; fixed in 2.20.2×1
- Balbooa Gridbox for Joomla, unauthenticated cookie-forgery authentication bypass to Super User×1
- Balbooa Gridbox for Joomla; registration handler adds caller-supplied usergroup IDs, letting an unauthenticated visitor register an account directly into an administrator group; CVSS 4.0 10.0 (CWE-284, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2×1
- Events Booking for Joomla, unauthenticated invoice IDOR exposing personal and financial data×1
- Joomla Events Booking×1
Where this entity is cited
Source distribution
- mysites.guru6 (86%)
- balbooa.com1 (14%)
External references
All cited sources (7)
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/easystore-security-disclosure/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/events-booking-invoice-idor/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/gridbox-23-critical-vulnerabilities/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/gridbox-author-sql-injection/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/gridbox-critical-authentication-bypass/
- mysites.guruprimarymySites.guruhttps://mysites.guru/blog/membership-pro-unauthenticated-file-upload/
- balbooa.comBalbooahttps://www.balbooa.com/blog/gridbox/gridbox-2-20-2-security-release