CVE-2026-56291
The Balbooa Forms extension for Joomla allows attackers to upload any file without authentication, including executable code, which can lead to full remote code execution. This flaw exists in versions older than 2.4.1 and can be exploited from the internet without any user interaction.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Joomla sites using the Balbooa Forms extension version 2.4.0 or earlier.
Real-world impact
An attacker can upload malicious files and run arbitrary code on the server, potentially taking full control of the website and its underlying system.
Why this severity
The CVSS score of 10 reflects the lack of authentication, the ability to execute arbitrary code, and the high impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Balbooa Forms to version 2.4.1 or later following vendor instructions.
- 02Restart the Joomla site if required.
- ›Disable or remove the Balbooa Forms extension until a patch is applied.
CISA KEV required action
Timeline
- Jul 9, 2026 · 26d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 10, 2026 · 25d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 13, 2026 · 22d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 23, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 24, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- mysites.guru/blog/balbooa-forms-unauthen…exploitthird party advisory
- balbooa.com/joomla-formsproduct
- cisa.gov/known-exploited-vulnerabili…us government resource