What is CVE-2026-65885?
This vulnerability is an authenticated arbitrary file upload in the Gridbox Joomla extension, affecting versions before 2.20.2. It can lead to authenticated Remote Code Execution (RCE) when combined with CVE-2026-65884. Users should update Gridbox to version 2.20.2 or later.
Azərbaycanca: Bu boşluq Gridbox Joomla genişlənməsinin autentifikasiya olunmuş istifadəçilər tərəfindən ixtiyari fayl yüklənməsinə imkan verən zəifliyidir. 2.20.2-dən əvvəlki versiyalar təsirlənir; CVE-2026-65884 ilə birlikdə autentifikasiya olunmuş uzaqdan kod icrasına (RCE) səbəb ola bilər. İstifadəçilər Gridbox-u ən azı 2.20.2 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which Joomla extension is affected by CVE-2026-65885?
This vulnerability affects the Gridbox Joomla extension in versions prior to 2.20.2.
What risk can CVE-2026-65885 pose when combined with CVE-2026-65884?
When combined with CVE-2026-65884, this vulnerability can lead to authenticated Remote Code Execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.