DIRAS TAKE
Urgent: this is a pre-auth remote code execution added to CISA’s Known Exploited Vulnerabilities catalog with a short federal mitigation deadline, so prioritize mitigation or removal of the extension immediately.
What is CVE-2026-56291?
Unauthenticated attackers can upload arbitrary files to Balbooa Forms and achieve remote code execution against the extension, allowing full control of affected Joomla sites. CVE-2026-56291 is an unauthenticated arbitrary file upload (CWE-434) in Balbooa Forms that permits uploading executable files and leads to RCE. Versions in the 1.x branch reported as 1.0 through 2.4.0 are affected. Exploitation requires only network access to the vulnerable upload functionality; no valid account or user interaction is required. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Balbooa Forms are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0-2.4.0 |
Is CVE-2026-56291 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-10 and U.S. federal agencies were required to mitigate by 2026-07-13. Public exploit code is available.
How to fix CVE-2026-56291
- Remove or disable the Balbooa Forms extension until vendor fixes are provided.
- If removal is not possible, restrict access to the Joomla site and upload endpoints from the internet (IP allowlist) and block file uploads.
- Deploy a web application firewall rule to block suspicious upload attempts and executable file types.
- Follow the vendor’s guidance and monitor logs and file systems for unexpected uploads and webshells.
Frequently asked questions
Is CVE-2026-56291 being actively exploited?
CVE-2026-56291 was added to CISA’s Known Exploited Vulnerabilities catalog on 2026-07-10 with a required mitigation date of 2026-07-13, and public exploit code is available.
Which Balbooa Forms versions are affected by CVE-2026-56291?
Balbooa Forms versions in the 1.x branch reported as 1.0 through 2.4.0 are listed as affected.
Is there a patch for CVE-2026-56291?
No fixed version is listed for CVE-2026-56291; the affected branch shows no fixed release, so apply mitigations or remove the extension per vendor guidance.
Does CVE-2026-56291 require authentication?
No; CVE-2026-56291 is an unauthenticated arbitrary file upload vulnerability in Balbooa Forms and does not require a valid account.
References
- nvd.nist.gov/vuln/detail/CVE-2026-56291
- cve.org/CVERecord?id=CVE-2026-56291
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56291
- balbooa.com/joomla-forms
- mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw
- All Balbooa CVEs on CVE Radar
- CVEs published in September 2026