Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
CVE-2026-56291
Verified
Description
Joomla Balbooa Forms contains an unrestricted file upload vulnerability caused by lack of authentication checks, letting unauthenticated attackers upload executable files and achieve remote code execution.
Severity
Critical
CVSS Score
9.8
Exploit Probability
15%
Affected Product
forms
Published Date
July 14, 2026
Template Author
nick vidovic, 0x_akoko
CVE-2026-56291.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-56291
CWE ID:
cwe-434
Remediation Steps
Update to the latest version of Balbooa Forms extension.