Knox CVE Database
/
CVE-2026-56291
Critical
9.8

CVE-2026-56291: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

Added to the CISA KEV catalog:
July 10, 2026

Overview

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Vulnerability details

Affected vendor
Balbooa
Affected product
Forms
Weakness type (CWE)
CWE-434

The Balbooa Forms extension for Joomla (com_baforms) versions up to and including 2.4.0 contains a CWE-434 unrestricted file upload vulnerability in its frontend attachment upload handler. The endpoint accepted files from any visitor with no authentication check, no CSRF token, and no file-extension allow-list. Because the handler trusted the caller-supplied filename, a submitted file was written directly to a publicly accessible directory on the server, where the web server would execute it as PHP code on request.


An attacker sends a crafted HTTP POST request to the Balbooa Forms upload handler containing a PHP webshell with an attacker-chosen filename, with no authentication credentials or CSRF token required. The file lands in a public directory and the attacker then requests it directly, achieving full remote code execution on the hosting server. This vulnerability was actively exploited in the wild as a zero-day before the patch existed, confirmed through a real web server access log showing the attack in progress. Upgrade to version 2.4.1 or later is required; the fixed-version boundary for this CVE is 2.4.1.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review web server access logs for POST requests to the com_baforms upload handler originating from sessions with no prior authentication event, particularly where the uploaded filename carries a .php or other executable extension.
  • Audit the Joomla filesystem under the Balbooa Forms component directories for PHP files that do not match any form template or plugin asset, especially files with randomized or generic names created after an anonymous POST request.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 13, 2026

Additional hardening

  • Upgrade Balbooa Forms to version 2.4.1 or later; the advisory notes that subsequent security releases followed, so consult the vendor advisory in References for the current minimum safe version.
  • After patching, audit the Joomla filesystem for stray PHP files in directories writable by the web server and check for unexpected administrator accounts that may indicate prior compromise.
  • Configure the web server to deny PHP execution in all upload and media directories used by Joomla extensions, so that any file placed there by a form handler cannot be executed even if file-type validation fails.
  • Restrict public network access to the Joomla frontend to known IP ranges where operationally feasible, reducing the pool of unauthenticated sources that can reach the upload endpoint.

Key dates

Published (NVD)
July 9, 2026
Added to CISA KEV
July 10, 2026
Remediation deadline
July 13, 2026
Last updated
July 24, 2026

References

Frequently asked questions

Does CVE-2026-56291 affect my FedRAMP authorization?

If Balbooa Forms runs inside your authorization boundary, CVE-2026-56291 is a direct concern for your FedRAMP authorization. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of July 13, 2026. An unpatched KEV within your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-56291?

Knox does not patch Balbooa Forms on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-56291 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-56291. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-56291 isn't remediated by July 13, 2026?

If CVE-2026-56291 is not remediated by July 13, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization in good standing and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting