## Overview
A critical vulnerability, CVE-2026-65884, affects the Gridbox extension for Joomla versions prior to 2.20.2. This flaw enables unauthenticated actors to exploit the registration method. By providing specific usergroup IDs, these attackers can register new accounts with administrative permissions.
## Technical Details
The vulnerability lies in the way Gridbox handles user registration. It allows users to specify usergroup IDs during account creation. If an attacker knows the ID for an administrative group, they can create an account with elevated privileges. This flaw has a CVSS score of 10.0, indicating its critical severity. The affected versions are all prior to 2.20.2.
## Impact
Successful exploitation of this vulnerability can lead to full administrative access to the Joomla site. Attackers could manipulate site content, access sensitive data, or further compromise the server. This poses a significant risk to any organization using the affected extension.
## Mitigation
Defenders should immediately update the Gridbox extension to version 2.20.2 or later. Regularly review user accounts and permissions to identify any unauthorized changes. Implement additional security measures such as two-factor authentication for administrative accounts to reduce the risk of exploitation.
CSURFACE Threat Sensor