2026-07-09HIGHexploitedBalbooa patches an actively-exploited unauthenticated file-upload RCE in its Joomla Forms extension, the third such flaw in the ecosystem in two weeks
Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0), zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave
cve · CVE-2026-56291
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
Balbooa patches an actively-exploited unauthenticated file-upload RCE in its Joomla Forms extension, the…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology
Sources cited
2
2 hosts
Action items (4)
Do-now tasks recorded on the entries about CVE-2026-56291, newest first. Check the date before acting on an older one.
- Inventory every Joomla site running Balbooa Forms and update all installs to 2.4.1 or later immediately, do not wait for a maintenance window; the flaw is being actively exploited.2026-07-09CVE-2026-56291
- Treat any site that ran 2.4.0 or earlier while exposed as possibly compromised: check images/baforms/uploads/ (and other per-component upload folders) for unexpected .php/.phtml files and check Joomla for unexpected Super User accounts.2026-07-09CVE-2026-56291
- At the web-server layer, deny PHP execution inside upload-only directories (nginx location block / Apache php_admin_flag engine off on images/ and media/ subpaths) regardless of vendor patch status, this closes the whole recurring bug class, not one component.2026-07-09CVE-2026-56291
- Hunt access logs for POST requests to index.php?option=com_baforms&task=form.uploadAttachmentFile returning HTTP 200 followed by a GET to a newly created executable file under the upload directory.2026-07-09CVE-2026-56291
Defender insights
What each entry about CVE-2026-56291 tells a defender to do, newest first.
Story timeline
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-09/cve-2026-56291-balbooa-forms-joomla-unauth-file-upload-rce · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-09/cve-2026-56291-balbooa-forms-joomla-unauth-file-upload-rce · ATT&CK page ↗
Entries about Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0), zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- balbooa.com1 (50%)
- mysites.guru1 (50%)