Vulnerability Details CVE-2026-65887
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-65887
-
cpe:2.3:a:balbooa:gridbox:2.20.1