CVE-2026-56291
CISA KEVAs of 2026-07-11, CVE-2026-56291 is a CVSS 9.8 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited); Public exploit code available. EPSS exploitation probability 0.8%. Threadlinqs Intelligence tracks 4 threats exploiting it.
Last updated: 2026-07-11
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-434
Exploitation status
CISA KEV-listed (known exploited) · public exploit code available
- shinthink/CVE-2026-56291 (github)
- trickest/cve (trickest)
Threats tracking this CVE
- CVE-2026-48939 & CVE-2026-56291: Perfect-10 Joomla Extension Bugs (iCagenda, Balbooa Forms) Actively Exploited, Added to CISA KEV — CRITICAL
- CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions — iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Arbitrary File Upload — CRITICAL
- CISA KEV: Joomla iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Unrestricted File Upload Flaws Under Active Exploitation — CRITICAL
- Zero-Day Exploitation of Joomla iCagenda and Balbooa Forms Extensions via Unauthenticated Arbitrary File Upload (CVE-2026-48939, CVE-2026-56291) — CRITICAL
References
- https://www.balbooa.com/joomla-forms
- https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.