Critical· 9.2official fix available
CVE-2026-65886
A security flaw in the Gridbox extension for Joomla allows unauthorized users to read sensitive files on the server. This vulnerability occurs because the photo viewer component does not properly restrict file access.
publishedJul 29, 2026
last modifiedJul 29, 2026
sourcesNVD
severity · cvss
9.2
critical · how bad it is
exploitation · epss
n/a
chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 28, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Users running the Gridbox extension for Joomla on versions earlier than 2.20.2.
02
Real-world impact
An attacker could access and read private files stored on your web server without needing a username or password, potentially exposing sensitive data.
03
Why this severity
This vulnerability is rated as critical because it allows an attacker to access sensitive files remotely over the internet without any authentication or user interaction.
04
What to do about it
official fix available
recommended steps
- 01Upgrade the Gridbox extension to version 2.20.2 or later.
NVD-referenced vendor advisory
05
Timeline
- Jul 29, 2026 · 21h agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 20h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactNone
Availability impactNone
07
References & advisories
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →