← Blog
🛡️ Vulnerability27 July 2026

CVE-2026-56291: critical flaw in Balbooa Forms for Joomla allows unauthenticated RCE

Critical vulnerability (CVSS 10) in Balbooa Forms for Joomla, listed in the CISA KEV catalog. What to do today if you use this plugin.

OCIRIA security team

CVE-2026-56291: critical flaw in Balbooa Forms for Joomla allows unauthenticated RCE

In short

A critical vulnerability (CVSS 10.0) has been published in the Balbooa Forms extension for Joomla, identified as CVE-2026-56291 [1]. It allows an attacker, without needing to authenticate, to upload executable files to the server and take remote control of the system. The vulnerability is listed in the CISA KEV catalog of known exploited vulnerabilities [2]. If your website uses Joomla with Balbooa Forms, this is a priority: identify whether the plugin is installed and update it today.

What it is and why it matters

CVE-2026-56291 is an unauthenticated arbitrary file upload flaw in the Balbooa Forms extension for Joomla, in versions prior to 2.4.1 [1]. The problem is that the form accepts file uploads without checking who is submitting them or what type of file it actually is. An attacker can exploit this to place a malicious file on the server and execute it, resulting in remote code execution (RCE): total control over the web server, not just the form.

The National Vulnerability Database (NVD) has rated this vulnerability with the maximum score, CVSS 10.0, and "critical" severity [1]. Additionally, the vulnerability has been added to the CISA KEV catalog, which lists vulnerabilities with confirmed active exploitation [2]. The combination of a maximum score and presence in KEV is, in itself, reason enough to treat this case as high priority.

Who is affected

It affects any organization using the Joomla content management system with the Balbooa Forms extension installed in a version earlier than 2.4.1, according to the official vulnerability description [1]. The affected vendor is Balbooa [1]. The source does not provide data on the number of active installations or on specific sectors most affected, so we cannot pinpoint that scope beyond what is stated: any Joomla site with this plugin publicly exposed on the internet is, in principle, susceptible.

How to know if you're vulnerable

As general guidance for this type of unauthenticated file upload vulnerability:

  • Check whether your Joomla site has the Balbooa Forms extension installed and which version is currently running.
  • Review the public forms on your website (contact, surveys, registration) to see if they use this extension.
  • Check your exposed attack surface: which plugins, extensions, and versions are visible from the internet is usually the first thing an attacker checks, and also the first thing you should check yourself before they do.

How to protect yourself

1. Update Balbooa Forms to the latest available version; the vulnerability affects versions prior to 2.4.1 [1].

2. If you can't update immediately, consider temporarily disabling the extension or restricting public access to the affected form until the update is completed.

3. Review access logs and the file upload directory for recent files with executable extensions or suspicious names, as recommended by OCIRIA's analysis of this CVE.

4. Verify that there are no unrecognized files or webshells on the server, especially in upload folders.

5. Apply the principle of least privilege to the user running the web server, to limit the impact should a malicious file be uploaded.

6. Maintain an up-to-date inventory of Joomla extensions and their versions to be able to react quickly to alerts like this one.

Frequently asked questions

Do I need to be authenticated to be attacked? No. The vulnerability allows the file to be uploaded without prior authentication, according to the official description [1].

Is this a theoretical vulnerability or is there real exploitation? The vulnerability is included in the CISA KEV catalog, which lists flaws with confirmed active exploitation [2].

How severe is this compared to other vulnerabilities? It has the maximum possible CVSS score, 10.0, and is classified as critical by the NVD [1].

Does it affect all of Joomla or just a plugin? It specifically affects the Balbooa Forms extension, not the Joomla core [1].

Sources

  • [1] https://nvd.nist.gov/vuln/detail/CVE-2026-56291
  • [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json
OCIRIA security team Threat monitoring & response · data from our real-time radar Live radar