Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-65886 – Unauthenticated Arbitrary File Read – Gridbox extension for Joomla < 2.20.2

Be the first to know when new zero-days emerge:

Summary

CVE-2026-65886 is a critical unauthenticated arbitrary file read vulnerability in the Gridbox page builder extension for Joomla, developed by balbooa.com, affecting all versions from 1.0.0 through 2.20.1. The flaw resides in the extension’s photo viewer component, which fails to properly restrict file path access, allowing any unauthenticated remote attacker to read arbitrary files from the server. With a CVSS 4.0 score of 9.2, this vulnerability requires no credentials, no user interaction, and is directly exploitable over the network against any internet-facing Joomla site running Gridbox.

Technical details

  • Root cause: Improper limitation of a pathname to a restricted directory (CWE-22 — Path Traversal) within the Gridbox photo viewer feature. The endpoint does not validate or sanitize the file path supplied by the requester, allowing traversal outside the intended directory.
  • Trigger conditions: The photo viewer is a front-end, publicly accessible feature. No authentication, session, or special preconditions are required to trigger the vulnerability.
  • Attack vector: Network — any unauthenticated attacker reachable over the internet can send a crafted request to the photo viewer endpoint to retrieve arbitrary server-side files.
  • Impact: Full confidentiality compromise of both the vulnerable component (VC:H) and downstream systems (SC:H). An attacker can read sensitive server files, including Joomla’s configuration.php (which contains database credentials, secret keys, and connection strings), system files such as /etc/passwd, application secrets, and other files accessible to the web server process. Credential exposure from such files commonly enables further lateral movement and full site or server compromise.

Affected software

  • Gridbox extension for Joomla (com_gridbox) by balbooa.com: versions 1.0.0 through 2.20.1 (inclusive)

Severity

  • CVSS 4.0 Base Score: 9.2 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Mitigation and recommended actions

  • Immediate action: Upgrade Gridbox to version 2.20.2 or later, which contains the vendor-issued fix for this vulnerability. Updates are available via the Joomla Extensions Directory or directly from balbooa.com.
  • Additional context: CVE-2026-65886 was disclosed on July 29, 2026, alongside several other critical Gridbox vulnerabilities in the same release batch — including CVE-2026-65884 (unauthenticated privilege escalation to Super User, CVSS 10.0) and CVE-2026-65885 (authenticated arbitrary file upload, CVSS 9.4) — all resolved in 2.20.2. Organizations should treat this as an urgent patch cycle covering multiple critical issues in a single update. Prior Balbooa vulnerabilities in the same product line — including CVE-2026-61425 (Gridbox authentication bypass, fixed in 2.20.1) and CVE-2026-56291 (Balbooa Forms unauthenticated file upload, CVSS 10.0, confirmed exploited as a zero-day and added to the CISA Known Exploited Vulnerabilities catalog) — have attracted rapid real-world exploitation, underscoring the urgency of patching this extension immediately.

IONIX Status

The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge