CVE-2026-56291
forms: Unrestricted Upload of File with Dangerous Type (CVE-2026-56291)
Situation assessment
A critical unrestricted file upload vulnerability in balbooa forms allows unauthenticated remote attackers to upload arbitrary files, leading to full remote code execution on the target system. No user interaction or prior authentication is required, making exploitation trivial for any network-reachable instance. The vulnerability is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog, confirming real-world attack activity. Organizations using balbooa forms should immediately verify exposure and apply available patches or mitigations without delay. Given the complete compromise of confidentiality, integrity, and availability, this warrants the highest remediation priority.
Affected
- balbooa/forms
lt *..2.4.1
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-56291 scores CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and sits at the 96.4th EPSS percentile, indicating a very high probability that automated exploitation attempts are already underway. The vulnerability requires no authentication and delivers direct remote code execution, making it an ideal target for opportunistic mass-scanning campaigns against Joomla installations. For NIS2-regulated organisations with publicly accessible Joomla instances — including public-sector bodies, healthcare providers, and critical infrastructure operators — the risk of full host compromise is immediate. Although CISA has not set the known-ransomware-campaign flag, a successful RCE foothold is a natural precursor to lateral movement and data exfiltration. Patching to 2.4.1 is the absolute priority; until that is possible, WAF-level upload blocking and disabling PHP execution in upload directories are mandatory compensating controls.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch immediately: Upgrade Balbooa Forms to version 2.4.1 or later — this is the only complete fix. Use the Joomla Extension Manager or download directly from balbooa.com.
- Inventory all Joomla instances: Identify every environment running Balbooa Forms < 2.4.1 across CMS inventories, web-server directories, and deployment pipelines. Prioritise internet-facing instances.
- Strip execute permissions from upload directories: Remove execution rights for the web-server process (Apache/Nginx) on all plugin upload target directories (
chmod o-x,noexecmount option, orOptions -ExecCGIdirective) as an immediate compensating control. - Audit recently uploaded files: Inspect the plugin's upload directories for PHP, PHTML, PHAR, JSP, or other executable files — pay particular attention to files created within the last 30 days.
- Retrospectively review web-server access logs: Examine POST requests to the Balbooa Forms endpoint (
/index.php?option=com_balbooaor equivalent) for suspicious filenames or Content-Type headers — look back at least 90 days. - Isolate potentially compromised instances: Any instance where executable files are found in upload directories must be taken offline and forensically preserved before patching.
Runbook · Step 2
Mitigation layers
- WAF rule — block dangerous uploads: Restrict multipart requests to Balbooa Forms endpoints to permitted MIME types (image/jpeg, image/png, application/pdf). ModSecurity:
SecRule FILES_NAMES "@rx \.(php|phtml|phar|php[0-9]|jsp|asp|aspx|sh|py|pl)$" "id:9001,phase:2,deny,msg:'Balbooa Forms dangerous upload blocked'". - Network segmentation: Place Joomla/Balbooa Forms web servers in a DMZ with no direct routes to internal systems (databases, AD/LDAP, internal APIs). Apply strict egress filtering on the web-server process to an allowlist of required destinations.
- Disable PHP execution in upload directories: Nginx:
location ~* /uploads/.*\.php { deny all; }— Apache:<Directory /var/www/html/uploads> php_admin_flag engine off </Directory>and protect with.htaccess. - Least-privilege for the web-server process: Ensure the web-server user (www-data, apache) cannot spawn interactive shells. Enforce AppArmor or SELinux profiles; restrict write access to explicitly required directories only.
- Harden the Joomla admin backend: Protect
/administratorwith an IP allowlist or MFA to prevent post-exploitation persistence (e.g., backdoor installation via the backend).
Runbook · Step 3
Detection rules
- Web-server access log — suspicious uploads: SPL:
index=web_logs method=POST uri="*com_balbooa*" | regex file_name="(?i)\.(php|phtml|phar|php\d|jsp|asp|sh|py)$"— escalate any match immediately. - Filesystem monitoring (auditd / Sysmon): Alert on new executable-extension files appearing in upload directories: auditd rule
-w /var/www/html/uploads -p wa -k balbooa_upload; Sysmon EID 11 (FileCreate) with TargetFilename matching*.php|*.phar|*.jsp. - Process ancestry (EDR): Web-server process (apache2, nginx, php-fpm) spawning unexpected child processes (
bash,sh,curl,wget,python): Sigma shapeParentImage|endswith: 'apache2' AND Image|contains: 'bash'(extend for sh, curl, wget, python). - Network telemetry (Zeek / Suricata): Outbound connections from the web-server host to external IPs on non-standard ports (reverse-shell pattern):
alert tcp $HTTP_SERVERS any -> $EXTERNAL_NET !80 !443 (msg:"Possible RCE reverse shell from webserver"; flow:established,to_server; sid:9002;). - Joomla log correlation: Correlate HTTP 200 responses to POST requests on
com_balbooawith a subsequent GET request to the same uploaded filename — this two-step pattern is characteristic of web-shell deployment and execution.
Description
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
2.4.1fixed from 2.4.1Metrics
Show all metrics
Weakness classes (CWE)
CWE-434Base
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Modified Analysis2026-07-24 13:30 UTC· nvd@nist.gov
- CVE Modified2026-07-23 16:17 UTC· security@joomla.org
- Description: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. → Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
- New CVE Received2026-07-09 11:16 UTC· security@joomla.org
- Affected: balbooa.com Balbooa Forms extension for Joomla
- Description: The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
- CWE: CWE-434