Skip to main content
Change Risk Intel

CVE-2026-56291 — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

CVSS
9.8 (Critical)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — Balbooa Forms is deployed on public Joomla marketing sites; remove or update the extension within 48 hours.
Affected products
Balbooa Forms

Why this one matters to a CAB

Balbooa Forms is a Joomla extension used on marketing sites, customer-facing product pages, and lightweight lead-capture landing pages — often the sites least loved by IT, most managed by Marketing, and most exposed. An unauthenticated file upload that leads to RCE on a public Joomla site is a webshell in less than a day.

Defender’s angle

  • Marketing inventory: the CAB’s first move is to ask Marketing to enumerate every Joomla site under their control. There is almost certainly one nobody remembered.
  • File-system delta: find /var/www -newer /var/log/lastknown -name "*.php" on the Joomla host will surface unexpected PHP files that appeared after the disclosure date. Any hit is an incident, not a change.
  • Contain, then patch: if the extension is deployed, add a WAF rule blocking the ?option=com_balbooaforms&task=upload request path until the update is confirmed installed.

What to bring to CAB

A joint IT + Marketing change record. Marketing owns the site, IT owns the change record, and Security owns the sign-off.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.