What is CVE-2026-65886?
CVE-2026-65886 is an unauthenticated arbitrary file read vulnerability in the Gridbox Joomla extension before version 2.20.2 via the photo viewer. This allows remote attackers to read arbitrary files on the server without authentication. Users should immediately update the Gridbox extension to the latest version.
Azərbaycanca: CVE-2026-65886, Joomla üçün Gridbox genişlənməsinin 2.20.2-dən əvvəlki versiyalarında foto görüntüleyici vasitəsilə autentifikasiya olunmadan istənilən faylın oxunması zəifliyidir. Bu, uzaqdan hücum edənlərə serverdəki ixtiyari faylları icazəsiz oxumağa imkan verir. İstifadəçilər dərhal Gridbox genişlənməsini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: balbooa.com
FAQ2
What type of attack is possible with CVE-2026-65886?
This vulnerability allows unauthenticated arbitrary file read, meaning a remote attacker can read arbitrary files on the server without authorization.
How can I protect against CVE-2026-65886?
Users should immediately update the Gridbox Joomla extension to version 2.20.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.