ctipilot.ch
← Back to Weekly 2026-W30
NOTABLEupdateNATOB2synthesis

Joomla third-party-extension vulnerability wave status: the mySites.guru campaign added a new technique class this week — a client-supplied cookie accepted as proof of identity, giving anonymous Super User access

discovered 2026-07-26 23:47 UTCrun 2026-07-26T2309Z-weekly2 sourcessingle-source

UPDATE · originally covered A researcher-driven Joomla extension file-upload wave produced four unauthenticated RCE disclosures this week — several exploited as zero-days before a patch existed (2026-07-12)

the researcher-driven Joomla third-party-extension vulnerability wave a prior weekly consolidated as a file-upload-to-RCE cluster continued this week, and the delta is a new technique class.

The mySites.guru campaign produced six further extension disclosures between 2026-07-20 and 2026-07-23, and the one that matters most is not another file upload. The Balbooa Gridbox page builder (CVE-2026-61425) accepts a client-supplied cookie value as proof of identity — mySites.guru describes a critical unauthenticated authentication bypass in Gridbox that lets anyone become a Super User by setting a single cookie value (mySites.guru, 2026-07-20). Because a Joomla Super User can edit templates, and editing a template is PHP execution, that cookie yields full site compromise from a single anonymous request; the flaw is fixed in Gridbox 2.20.1 and the vulnerable code had shipped since October 2025. Alongside it the week added an unauthenticated upload in Membership Pro, unauthenticated SQL injection and an order-forgery flaw in EasyStore, and an invoice IDOR in Events Booking.

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1505.003Server Software Component: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.