CVE-2026-65880: pre-auth remote code execution in balbooa.com Balbooa Forms component for Joomla

An unauthenticated attacker can execute arbitrary code against the Balbooa Forms component for Joomla (CVE-2026-65880). The vulnerability is a code-injection issue (CWE-94) affecting Balbooa Forms 1.x versions 1.0.0 through 2.4.2.1 and stems from form processing for the signature field type. No authentication is required; an attacker only needs network access to submit crafted form data to a vulnerable installation.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 4.0
10CRITICAL
EPSS
0.00772
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: the flaw allows remote code execution without any login, so immediately restrict public access to affected endpoints and follow vendor guidance as soon as updates or mitigations are published.

What is CVE-2026-65880?

An unauthenticated attacker can execute arbitrary code against the Balbooa Forms component for Joomla (CVE-2026-65880). The vulnerability is a code-injection issue (CWE-94) affecting Balbooa Forms 1.x versions 1.0.0 through 2.4.2.1 and stems from form processing for the signature field type. No authentication is required; an attacker only needs network access to submit crafted form data to a vulnerable installation.

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of balbooa.com Balbooa Forms component for Joomla are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0-2.4.2.1

Is CVE-2026-65880 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-65880

  1. Remove or disable use of the signature field type in Balbooa Forms if feasible.
  2. Restrict external access to the Joomla site or block requests to form-processing endpoints at the network or web application firewall level.
  3. Monitor web and application logs for suspicious form submissions and signs of remote code execution.
  4. Follow the vendor's guidance and apply an official patch or upgrade as soon as Balbooa provides a fixed release.

Frequently asked questions

Is CVE-2026-65880 being actively exploited?

There are no public reports of active exploitation of CVE-2026-65880 as of 2026-09-29.

Which Balbooa Forms component for Joomla versions are affected by CVE-2026-65880?

Balbooa Forms for Joomla 1.x versions from 1.0.0 through 2.4.2.1 are listed as affected by CVE-2026-65880.

Is there a patch for CVE-2026-65880?

No fixed version is listed for CVE-2026-65880; a vendor-provided patch or fixed release is not available in the provided facts.

Does CVE-2026-65880 require authentication?

No; the vulnerability in Balbooa Forms does not require authentication and can be triggered by unauthenticated form submissions.

References