Vulnerability record · CVE-2026-56291 · published 9 July 2026
CVE-2026-56291: Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCE
Balbooa · Forms
The Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing executable files to be placed on the server. Because the uploaded file can be executed, this leads to full remote code execution on the hosting web server.
Description
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary file upload leading to full RCE, with a CVSS 4.0 score of 10, KEV listing and a public exploit reference.
What it is
The Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing executable files to be placed on the server. Because the uploaded file can be executed, this leads to full remote code execution on the hosting web server.
Impact
An unauthenticated attacker can upload and execute arbitrary code, gaining full control of the Joomla site and potentially the underlying host. This enables data theft, defacement, persistence and use of the server as a foothold for further attacks.
Attack surface
Reachable over the network through the Joomla site's HTTP interface with no authentication and no user interaction required, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). Any internet-exposed Joomla installation running the vulnerable Balbooa Forms extension is a candidate target.
Exploitation
The vulnerability is listed in CISA KEV with a due date of 2026-07-13, and a public exploit reference is tagged Exploit, indicating active exploitation. EPSS gives a 30-day probability of 0.14854 (96.5th percentile), consistent with meaningful exploitation activity.
What to do
- Upgrade Balbooa Forms to version 2.4.1 or later immediately.
- If patching is not possible, disable or remove the Balbooa Forms extension until it can be updated.
- Block or restrict upload endpoints at the web application firewall and disallow execution of uploaded files in upload directories.
- Apply CISA BOD 26-04 guidance and, if no mitigation is available, discontinue use of the product.
- Review server file permissions and web server configuration to prevent script execution in writable upload paths.
Detection
- Monitor web server and Joomla logs for POST requests to Balbooa Forms upload endpoints, especially from unauthenticated sessions.
- Alert on newly created executable files (PHP, JSP, etc.) in upload or media directories.
- Hunt for unexpected outbound connections or web shell activity originating from the Joomla host.
- Correlate file creation events with subsequent process execution by the web server user.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-56291 to the Known Exploited Vulnerabilities catalog on 10 July 2026 as "Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 13 July 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/ | ExploitThird Party Advisory |
| https://www.balbooa.com/joomla-forms | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56291 | US Government Resource |
Track CVE-2026-56291 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-56291), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.