Security
Critical Gridbox authentication bypass fixed in Joomla extension
A critical authentication bypass in Balbooa’s Gridbox extension for Joomla allowed unauthenticated visitors to obtain Super User access by setting a browser cookie. The issue was fixed in 2.20.1, but administrators should now install…
mySites.guru published the research and assigned the original flaw CVE-2026-61425 through the Joomla CNA. It is classified as an unauthenticated authentication bypass with critical severity. The report says the weakness affected Gridbox releases below 2.20.1; Balbooa released that version on 20 July 2026.
The researchers confirmed the problem against a live Joomla installation. The report does not say that this specific bypass is being actively exploited, but says a later audit found 23 further Gridbox vulnerabilities, several of which were actively exploited. CVE records for that group list 1.0.0 through 2.20.1 as affected.
- Update every affected installation immediately.
- Install the latest release,
2.20.2.3, rather than stopping at2.20.1. - Review sites that ran vulnerable versions for signs of unauthorized access or changes.
Because the flaw could grant Super User privileges, a compromised site may have allowed changes to PHP-based templates and broader takeover.
Originally reported by mySites.guru.