What is CVE-2026-65888?
This vulnerability affects the Joomla Gridbox extension by balbooa.com in versions prior to 2.20.2. It involves an account takeover flaw where the socialLogin method allows malicious actors to log in as any user on the target site. Immediate update to the latest Gridbox version is strongly advised.
Azərbaycanca: Bu boşluq balbooa.com-un Joomla Gridbox genişlənməsinin 2.20.2-dən əvvəlki versiyalarında aşkarlanıb. socialLogin metodu vasitəsilə təcavüzkarlara saytda istənilən istifadəçi adı ilə daxil olmağa imkan verir. Dərhal Gridbox-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: balbooa.com
FAQ2
What software is affected by the CVE-2026-65888 vulnerability?
This vulnerability affects the Joomla Gridbox extension by balbooa.com in versions prior to 2.20.2.
What threat does CVE-2026-65888 pose?
It is an account takeover flaw where the socialLogin method allows malicious actors to log in as any user on the target site.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.