What is CVE-2026-65884?
CVE-2026-65884 is a privilege escalation vulnerability in the Gridbox extension for Joomla versions below 2.20.2. The registration method improperly handles user group IDs, enabling unauthenticated actors to register new accounts with administrative permissions. Users should upgrade to the latest version immediately.
Azərbaycanca: CVE-2026-65884, Joomla üçün Gridbox genişlənməsində (2.20.2 versiyasından əvvəl) imtiyaz artımı zəifliyidir. Qeydiyyat metodu istifadəçi qrupu ID-lərini səhv idarə edərək, autentifikasiya olunmamış şəxslərə administrator səlahiyyətləri olan yeni hesablar yaratmağa imkan verir. Gridbox istifadəçiləri dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of the Gridbox extension for Joomla are affected by CVE-2026-65884?
This vulnerability affects all versions of the Gridbox extension prior to 2.20.2.
What can an unauthenticated actor achieve by exploiting CVE-2026-65884?
An unauthenticated actor can register a new account with administrative permissions due to the flaw in the registration method.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.