CVE-2026-56291
published 2026-07-09CVE-2026-56291: Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-13
Exploited in the wild
EPSS
76.07%
99.5th percentile
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| balbooa.com | balbooa.com_balbooa_forms_extension_for_joomla | — | — |
| balbooa | forms | < 2.4.1 | 2.4.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability allows unauthenticated arbitrary file upload of executable files to the Balbooa Forms Joomla extension, leading to full RCE. Monitor for unexpected executable file uploads (e.g., PHP webshells) via the Balbooa Forms upload endpoint. ↗
- →The upload is unauthenticated — no session or authentication token is required. Alert on file upload requests to Balbooa Forms endpoints from unauthenticated sessions that result in executable file types being written to disk. ↗
- ·Vendor advisory and patch details are referenced but no specific patched version number or configuration mitigation is provided in the available sources. Consult the vendor directly for version-specific guidance. ↗
- ·CISA mandates forensic triage for affected assets in addition to patching, per BOD 26-04 requirements. Stakeholders must evaluate internet exposure of affected Joomla instances. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
balbooa Forms Plugin up to 2.4.0 File Upload unrestricted upload
vuldb·2026-07-10·CVSS 9.8
CVE-2026-56291 [CRITICAL] balbooa Forms Plugin up to 2.4.0 File Upload unrestricted upload
A vulnerability categorized as critical has been discovered in balbooa Forms Plugin up to 2.4.0. This vulnerability affects unknown code of the component File Upload. Executing a manipulation can lead to unrestricted upload.
This vulnerability is tracked as CVE-2026-56291. The attack can be launched remotely. Moreover, an exploit is present.
GHSA
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
ghsa_unreviewed·2026-07-09
CVE-2026-56291 [CRITICAL] CWE-434 The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
VulnCheck
Unrestricted Upload of File with Dangerous Type
vulncheck·2026·CVSS 10.0
CVE-2026-56291 [CRITICAL] Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Affected: balbooa.com Balbooa Forms extension for Joomla
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
CISA
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
cisa·2026-07-10·CVSS 9.8
CVE-2026-56291 [CRITICAL] CWE-434 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Vulnerability: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Affected: Balbooa Forms
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence t
No detection rules found.
Nuclei
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
nuclei·CVSS 9.8
CVE-2026-56291 [CRITICAL] Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
Joomla Balbooa Forms contains an unrestricted file upload vulnerability caused by lack of authentication checks, letting unauthenticated attackers upload executable files and achieve remote code execution.
Template:
id: CVE-2026-56291
info:
name: Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
author: Nick Vidovic,0x_Akoko
severity: critical
description: |
Joomla Balbooa Forms contains an unrestricted file upload vulnerability caused by lack of authentication checks, letting unauthenticated attackers upload executable files and achieve remote code execution.
impact: |
Unauthenticated attackers can upload executable files, leading to full remote code execution and complete system compromise.
remediation: |
Updat
2026-07-09
Published
2026-07-10
Added to CISA KEV
Exploited in the wild