CVE-2026-61425 CRITICAL

CVE-2026-61425: Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0

Vendor Balbooa.com
Product Gridbox extension for Joomla
Weakness CWE-288
Published July 20, 2026
Last update July 23, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

Explanation of Vulnerability in Simple Terms

02Summary

The Gridbox extension for Joomla contains an authentication bypass vulnerability affecting version 1.0.0-2.20.0.2. An attacker with high-level privileges can exploit this flaw to gain unauthorized access to sensitive functionality. The vulnerability requires network access but no user interaction. Site administrators should update to a patched version when available.

What an attacker can do

03Attacker Capabilities

Bypass authentication controls to access restricted functionality within the Gridbox extension.

Potential impact on your site

04Site Impact

Administrators with high privileges could exploit this to access unauthorized features; update when patched version is released.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrative privileges on the Joomla site.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE