CVE-2026-56291
KEV PoCUnauthenticated File Upload RCE in Balbooa Forms (Joomla)
CISA: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291 is an unauthenticated unrestricted file upload flaw (CWE-434) in the Balbooa Forms extension for Joomla, affecting versions prior to 2.4.1. Because the upload functionality requires no authentication, any remote attacker who can reach a site running the extension can upload arbitrary files, including executable file types, to the web server. Uploaded executable files can subsequently be invoked on the server, resulting in full remote code execution with high impact on confidentiality, integrity, and availability. Any Joomla site running Balbooa Forms below version 2.4.1 is affected, particularly those whose upload functionality is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-10 after reportedly being exploited as a zero-day, and a public proof-of-concept write-up is available.
What to do: Upgrade Balbooa Forms to version 2.4.1 or later immediately, as patching is the required action under CISA KEV/BOD 26-04 guidance. If upgrading is not immediately possible, restrict unauthenticated access to the extension's upload functionality at the web server or WAF layer and inspect upload directories for unexpected executable files that would indicate compromise. Review web logs for unauthenticated upload requests from unknown sources and treat any findings as potential RCE incidents.
| Balbooa Forms (Joomla extension) | < 2.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
- Affected
- Balbooa Forms
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Due date
- Ransomware use
- Unknown
- Vendors
- balbooa
- Products
- forms
- Ecosystems
- Joomla
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red