CVE-2026-65884
A flaw in the Gridbox extension for Joomla lets anyone create an administrator account without logging in. The issue exists in versions before 2.20.2 and can be fixed by updating the extension.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Joomla website owners who have the Gridbox extension installed, especially those using versions older than 2.20.2.
Real-world impact
An attacker could create a new admin account and gain full control over the Joomla site, allowing them to modify content, change settings, and access sensitive data.
Why this severity
The CVSS score of 10 reflects that the vulnerability can be exploited remotely without authentication, grants complete administrative privileges, and has no mitigations. The high impact on confidentiality, integrity, and availability justifies the critical rating.
What to do about it
- 01Upgrade the Gridbox extension to version 2.20.2 or later.
NVD description
Timeline
- Jul 29, 2026 · 23h agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 22h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.