What is CVE-2026-65889?
This critical vulnerability affects balbooa.com's Joomla extension in versions before 2.20.2. An unauthenticated actor can recursively delete directories on the server via the 'generateNewApp' method. Immediate update to the latest version is strongly recommended.
Azərbaycanca: Bu kritik boşluq balbooa.com-un Joomla genişlənməsinin 2.20.2-dən əvvəlki versiyalarında aşkarlanıb. Təsdiqlənməmiş şəxs 'generateNewApp' metodu vasitəsilə serverdəki qovluqları rekursiv şəkildə silə bilər. Dərhal genişlənməni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: balbooa.com
FAQ2
Which versions of the balbooa.com extension are affected by CVE-2026-65889?
This critical vulnerability affects balbooa.com's Joomla extension in versions before 2.20.2.
What can an actor exploiting CVE-2026-65889 do on the server?
An unauthenticated actor can recursively delete directories on the server via the 'generateNewApp' method.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.