Vulnary
← back to the feed
Critical· 9.2official fix available

CVE-2026-65886

A security flaw in the Gridbox extension for Joomla allows unauthorized users to read sensitive files on the server. This vulnerability occurs because the photo viewer component does not properly restrict file access.

publishedJul 29, 2026
last modifiedJul 29, 2026
sourcesNVD
severity · cvss
9.2
critical · how bad it is
exploitation · epss
n/a
chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 28, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users running the Gridbox extension for Joomla on versions earlier than 2.20.2.

02

Real-world impact

An attacker could access and read private files stored on your web server without needing a username or password, potentially exposing sensitive data.

03

Why this severity

This vulnerability is rated as critical because it allows an attacker to access sensitive files remotely over the internet without any authentication or user interaction.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Gridbox extension to version 2.20.2 or later.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 29, 2026 · 21h ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 29, 2026 · 20h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →