External risk intelligence

Gridbox Unauthenticated Password Reset Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-65887

The vulnerability exists in a Joomla extension, which is a component of a web application. Web applications and their associated extensions are commonly deployed as internet-facing services, making the vulnerable functionality reachable from the public internet in standard deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in a Joomla extension that allows unauthenticated users to reset any user's password, except for super administrators. This could permit unauthorized access and actions on behalf of other users.

  • Anyone can reset user passwords.
  • It allows unauthorized account takeover.
  • Confirm relevance and exposure to your systems.

Attack Path

How an attacker could exploit the issue

An attacker can remotely reset any user's password by interacting with the `resetPassword` method, enabling them to log in as the targeted user, except for super administrators.

  • Unauthenticated access required.
  • Vulnerable `resetPassword` method.
  • Takeover of non-admin accounts.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated actor to reset any user's password, except for super administrators. When exploited, this could enable an attacker to log in as a regular user and perform actions on their behalf.

  • User account access.
  • Unauthenticated password reset.
  • Unauthorized user actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Joomla extension owner and platform teams are likely responsible for addressing this critical vulnerability. The first practical step is to identify all Gridbox installations, confirm their exposure and business criticality, and then prioritize remediation based on risk, coordinating with the vendor as needed.

  • Application owners must manage the issue.
  • Verify Gridbox reachability and asset criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Gridbox Joomla extension?

Gridbox is a website builder extension designed for the Joomla content management system. It provides users with tools to create layouts, pages, and dynamic web content directly within a Joomla environment. Developers and site administrators use it to simplify the design process for various types of web projects, effectively acting as an add-on that extends the core functionality of the host CMS.

What does CVE-2026-65887 mean?

This CVE refers to a critical flaw categorized as Improper Access Control (CWE-284). In simple terms, the software fails to verify who is making a request. Because of this weakness, the system incorrectly trusts incoming commands, allowing unauthorized parties to bypass authentication checks that are normally required to modify user account settings.

How can an attacker trigger this vulnerability?

An attacker triggers the bug by sending a specific request to the resetPassword method within the affected Gridbox software. This process requires no login credentials or prior account access. Note that the vulnerability does not allow for the takeover of super administrator accounts; the reset function is restricted to targeting other, non-admin user roles within the system.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal labels this as an external threat. Because Gridbox is a web application extension, it is frequently deployed on sites accessible from the public internet. If your Joomla installation is reachable from the outside, the vulnerable component is likely exposed to remote requests, increasing the relevance of this issue for your environment.

What should I do if I use Gridbox?

The immediate priority is to locate all instances of Gridbox running on your systems to understand your current footprint. Once identified, evaluate the criticality of these installations to your business operations. Work closely with your platform team to coordinate with Balbooa for official updates or patches, and monitor your environment for any unauthorized changes to user account settings.

References