---
schema: 1
kind: vulnerability
title: "CVE-2026-56291 — Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)"
headline: "Balbooa patches an actively-exploited unauthenticated file-upload RCE in its Joomla Forms extension — the third such flaw in the ecosystem in two weeks"
summary: >
  Balbooa Forms (the com_baforms Joomla component) up to and including 2.4.0 exposed its
  frontend attachment-upload handler to any anonymous visitor with no authentication, no CSRF
  token, and no file-extension allow-list, allowing a .php upload to be written into a
  web-served directory and executed — unauthenticated RCE (CWE-434). It was exploited as a
  zero-day before the 2.4.1 fix (9 July 2026) and attacks continue against unpatched sites.
  Anyone running Joomla with Balbooa Forms should update to 2.4.1 now and check for tampering.
discovered_at: "2026-07-09T12:20:00Z"
event_date: "2026-07-08"
run_id: 2026-07-09T1211Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, actively-exploited, zero-day, pre-auth, path-traversal, patch-available]
regions: [global]
sectors: [public-sector, technology]
entities: [trend:joomla-extension-file-upload-rce-wave]
cves:
  - id: CVE-2026-56291
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "≤ 2.4.0"
    fixed: "2.4.1"
sources:
  - url: "https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/"
    publisher: "mySites.guru"
    date: "2026-07-08"
    role: primary
  - url: "https://www.balbooa.com/help/joomla-forms-documentation/basics/changelog"
    publisher: "Balbooa (vendor changelog)"
    date: "2026-07-09"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This was a zero-day: it was already being exploited in the wild when we found it, before any patch existed, and those attacks are still going on now against sites that have not updated."
    publisher: "mySites.guru"
  - quote: "The flaw was an unauthenticated file upload with no file-type allow-list."
    publisher: "mySites.guru"
verification: multi-source
sourcing_note: "Primary is the disclosing researcher (mySites.guru); CVE-2026-56291 confirmed on CVE.org/NVD (CWE-434, CVSS 4.0 base 10.0); the fix and affected/fixed versions confirmed against Balbooa's 2.4.1 changelog. No public proof-of-concept has been released."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Inventory every Joomla site running Balbooa Forms and update all installs to 2.4.1 or later immediately — do not wait for a maintenance window; the flaw is being actively exploited."
  - "Treat any site that ran 2.4.0 or earlier while exposed as possibly compromised: check images/baforms/uploads/ (and other per-component upload folders) for unexpected .php/.phtml files and check Joomla for unexpected Super User accounts."
  - "At the web-server layer, deny PHP execution inside upload-only directories (nginx location block / Apache php_admin_flag engine off on images/ and media/ subpaths) regardless of vendor patch status — this closes the whole recurring bug class, not one component."
  - "Hunt access logs for POST requests to index.php?option=com_baforms&task=form.uploadAttachmentFile returning HTTP 200 followed by a GET to a newly created executable file under the upload directory."
migrated_from: null
---

Balbooa Forms is a widely deployed drag-and-drop form builder for Joomla, installed as the `com_baforms` component for contact, registration and survey forms on thousands of sites, including the SME and municipal/public-sector Joomla estates common across Switzerland and Europe. Up to and including version 2.4.0, its frontend attachment-upload task — reached at `index.php?option=com_baforms&task=form.uploadAttachmentFile` — ran for any anonymous visitor with no authentication check, no `Session::checkToken()` CSRF validation, and no allow-list on the uploaded file's extension ([mySites.guru, 2026-07-08](https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/)). The write routine (`FormModel::uploadAttachmentFile`, around line 122 of the frontend `FormModel.php`) took the extension from the attacker-supplied filename and sanitised only the name portion with Joomla's `File::makeSafe()` — which strips dangerous characters but does not reject a `.php` extension — then rejoined the cleaned name with the untouched extension and wrote the file under `images/baforms/uploads/form-<id>/`, a directory that is served directly and executes PHP. The result is unauthenticated arbitrary-file-upload-to-RCE (CWE-434), the highest-severity web outcome, requiring no account of any kind; Joomla's CNA scored it CVSS 4.0 base 10.0 (`AV:N/AC:L/AT:N/PR:N/UI:N`).

This was a genuine zero-day: it surfaced when a mySites.guru customer brought in a raw web-server access log after a Hetzner hosting-abuse report, showing a successful exploit attempt before any patch existed, and the researchers state the same attacks continue against unpatched sites, with no public proof-of-concept released ([mySites.guru, 2026-07-08](https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/)). Balbooa fixed it the same day it was disclosed, shipping 2.4.1 on 9 July 2026 with four layered changes — a server-side extension allow-list per upload field, an optional MIME-type check, a server-generated stored filename (defeating double-extension tricks), and a CSRF token check ([Balbooa changelog, 2026-07-09](https://www.balbooa.com/help/joomla-forms-documentation/basics/changelog)); the flaw is tracked as CVE-2026-56291 (CWE-434, CVSS 4.0 base 10.0). Notably, the changelog lists these as ordinary "Fixed" items — one bullet mentions improving upload security — but nowhere flags that they close an actively-exploited remote code execution flaw or references the CVE, so update-triage that waits for an explicit severity or exploitation signal would leave the door open.

This is the third unrelated Joomla third-party extension disclosed with the identical unauthenticated file-upload-to-RCE class in roughly two weeks — following JoomShaper SP Page Builder (CVE-2026-48908) and Joomlack Page Builder CK (CVE-2026-56290), both added to CISA KEV on 7 July and both covered by this pipeline on 2026-07-08 — and all three were surfaced by the same research outfit. The pattern is now a defender action in its own right: the exposure is not one named component but the class of anonymous-facing upload endpoints across a Joomla estate's third-party extensions. Mapped to `T1190 Exploit Public-Facing Application` for the upload/execution and `T1505.003 Web Shell` once the uploaded file is used for persistence. **Defender takeaway:** patch Balbooa Forms to ≥2.4.1 now, treat prior-version installs as possibly compromised, and structurally deny PHP execution in upload directories and inventory every extension that accepts anonymous file uploads — the KEV-listed predecessors show this class is being weaponised at scale, not opportunistically.
