CRITICAL
CVE-2026-56291
CVSS
9.8
KEV
Description
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Summary dbcve.org
The Balbooa Forms Joomla extension versions before 2.4.1 contains an unauthenticated arbitrary file upload vulnerability. Attackers can upload executable files without any authentication, achieving full remote code execution on the affected Joomla instance.
Mitigation
Update Balbooa Forms extension to version 2.4.1 or later to remediate this vulnerability.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
14.85%
Probability of exploitation in next 30 days
96.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.