Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Critical Gridbox authentication bypass fixed in Joomla extension

A critical authentication bypass in Balbooa’s Gridbox extension for Joomla allowed unauthenticated visitors to obtain Super User access by setting a browser cookie. The issue was fixed in 2.20.1, but administrators should now install…

mySites.guru published the research and assigned the original flaw CVE-2026-61425 through the Joomla CNA. It is classified as an unauthenticated authentication bypass with critical severity. The report says the weakness affected Gridbox releases below 2.20.1; Balbooa released that version on 20 July 2026.

The researchers confirmed the problem against a live Joomla installation. The report does not say that this specific bypass is being actively exploited, but says a later audit found 23 further Gridbox vulnerabilities, several of which were actively exploited. CVE records for that group list 1.0.0 through 2.20.1 as affected.

  • Update every affected installation immediately.
  • Install the latest release, 2.20.2.3, rather than stopping at 2.20.1.
  • Review sites that ran vulnerable versions for signs of unauthorized access or changes.

Because the flaw could grant Super User privileges, a compromised site may have allowed changes to PHP-based templates and broader takeover.

Originally reported by mySites.guru.