cbcvebase.
CVE-2026-56291
published 2026-07-09

CVE-2026-56291: Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-13
Exploited in the wild
EPSS
76.07%
99.5th percentile
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Affected

2 ranges
VendorProductVersion rangeFixed in
balbooa.combalbooa.com_balbooa_forms_extension_for_joomla
balbooaforms< 2.4.12.4.1

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability allows unauthenticated arbitrary file upload of executable files to the Balbooa Forms Joomla extension, leading to full RCE. Monitor for unexpected executable file uploads (e.g., PHP webshells) via the Balbooa Forms upload endpoint.
  • The upload is unauthenticated — no session or authentication token is required. Alert on file upload requests to Balbooa Forms endpoints from unauthenticated sessions that result in executable file types being written to disk.
  • ·Vendor advisory and patch details are referenced but no specific patched version number or configuration mitigation is provided in the available sources. Consult the vendor directly for version-specific guidance.
  • ·CISA mandates forensic triage for affected assets in addition to patching, per BOD 26-04 requirements. Stakeholders must evaluate internet exposure of affected Joomla instances.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.