What is CVE-2026-65887?
This vulnerability exists in the Gridbox Joomla extension by balbooa.com in versions below 2.20.2. It allows an unauthenticated attacker to reset the password of any user, excluding super admins, via the `resetPassword` method and subsequently log in as that user. To mitigate this, it is strongly recommended to immediately update the Gridbox extension to the latest version.
Azərbaycanca: Bu boşluq balbooa.com Gridbox Joomla əlavəsinin 2.20.2-dən aşağı versiyalarında aşkarlanıb. Autentifikasiya olunmamış şəxs `resetPassword` metodu vasitəsilə super adminlər istisna olmaqla istənilən istifadəçinin parolunu sıfırlaya və həmin hesaba daxil ola bilir. Təsirə məruz qalmamaq üçün Gridbox əlavəsini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: balbooa.com
FAQ2
What action should be taken to avoid being affected by CVE-2026-65887?
To mitigate this, it is strongly recommended to immediately update the Gridbox Joomla extension by balbooa.com to the latest version.
Can the password of super admin accounts be reset in the CVE-2026-65887 vulnerability?
No, this vulnerability allows resetting the password of any user excluding super admins.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.