CVE-2026-56291

CRITICAL KEV NUCLEI

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-56291 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 10, 2026. EIP tracks 6 public exploits from researchers including ChiefYoru, HORKimhab, 0xdenis77. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets CVE-2026-56291, a pre-authentication remote code execution vulnerability in Balbooa Forms Joomla extension. It abuses the `form.uploadAttachmentFile` endpoint to upload a malicious PHP webshell by bypassing file type restrictions.

Description

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Exploits (6)

github WORKING POC
by ChiefYoru · pythonpoc
https://github.com/ChiefYoru/CVE-2026-56291_PoC

This exploit targets CVE-2026-56291, a pre-authentication remote code execution vulnerability in Balbooa Forms Joomla extension. It abuses the `form.uploadAttachmentFile` endpoint to upload a malicious PHP webshell by bypassing file type restrictions.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Balbooa Forms Joomla extension (unspecified version, likely vulnerable versions prior to patch)
No auth needed
Prerequisites: Target must have Balbooa Forms Joomla extension installed · Attacker needs network access to the target Joomla instance · Target must not have applied the patch for CVE-2026-56291
mistral-large-3 · analyzed Jul 19, 2026 Full analysis →
github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/56xxx/CVE-2026-56291.md

The repository contains a placeholder markdown file for CVE-2026-56291, describing an unauthenticated arbitrary file upload vulnerability in the Balbooa Forms Joomla extension (< 2.4.1) leading to RCE. However, no functional exploit code or technical details are provided.

Classification
Stub 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Joomla Balbooa Forms extension < 2.4.1
No auth needed
Prerequisites: Access to a vulnerable Joomla instance with Balbooa Forms extension installed (< 2.4.1)
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →
github WORKING POC
by 0xdenis77 · pythonpoc
https://github.com/0xdenis77/CVE-2026-56291

This repository contains a functional exploit for CVE-2026-56291, an unauthenticated arbitrary PHP file upload vulnerability in Balbooa Forms Joomla component (< 2.4.1). The exploit leverages the `form.uploadAttachmentFile` task to upload malicious PHP files and achieve remote code execution (RCE).

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Balbooa Forms Joomla component (com_baforms) versions < 2.4.1
No auth needed
Prerequisites: Target must have Balbooa Forms Joomla component installed (versions < 2.4.1) · Attacker must be able to send HTTP requests to the target
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →
github SCANNER
by rimbadirgantara · poc
https://github.com/rimbadirgantara/CVE-2026-56291.yaml

This YAML file is a Nuclei template designed to detect the presence of Balbooa Forms Joomla component (com_baforms) and extract version information. It does not exploit the vulnerability but identifies targets vulnerable to CVE-2026-56291, an unauthenticated arbitrary PHP file upload leading to RCE.

Classification
Scanner 99%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Balbooa Forms Joomla component (com_baforms) versions < 2.4.1
No auth needed
Prerequisites: Target must have the Balbooa Forms Joomla component installed and accessible over HTTP
mistral-large-3 · analyzed Jul 13, 2026 Full analysis →
nomisec WORKING POC
by shinthink · remote
https://github.com/shinthink/CVE-2026-56291

This repository contains a functional exploit for CVE-2026-56291, a pre-authentication arbitrary file upload vulnerability in Balbooa Forms Joomla extension (< 2.4.1). The exploit leverages the unprotected `form.uploadAttachmentFile` task to upload PHP shells and achieve remote code execution (RCE).

Classification
Working Poc 99%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Balbooa Forms (com_baforms) Joomla extension versions 1.0 to 2.4.0
No auth needed
Prerequisites: Target must have Balbooa Forms Joomla extension installed (versions < 2.4.1) · Attacker must be able to send HTTP requests to the target
mistral-large-3 · analyzed Jul 13, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/0xdenis77/CVE-2026-56291.yaml

This repository contains a functional exploit for CVE-2026-56291, an unauthenticated arbitrary PHP file upload vulnerability in Balbooa Forms Joomla component (< 2.4.1). The exploit leverages the `form.uploadAttachmentFile` task to upload malicious PHP files and achieve remote code execution (RCE).

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Balbooa Forms Joomla component (com_baforms) versions < 2.4.1
No auth needed
Prerequisites: Target must have Balbooa Forms Joomla component installed and accessible · Upload directory must be writable and PHP execution enabled
mistral-large-3 · analyzed Jul 15, 2026 Full analysis →

Nuclei Templates (1)

Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload
CRITICALby Nick Vidovic,0x_Akoko
FOFA: body="com_baforms"

Scores

CVSS v3 9.8
EPSS 0.7607
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-10
VulnCheck KEV 2026-07-08
ENISA EUVD EUVD-2026-42573
CWE
CWE-434
Status published
Products (2)
balbooa/forms < 2.4.1
balbooa.com/balbooa.com Balbooa Forms extension for Joomla 1.0-2.4.0
Published Jul 09, 2026
KEV Added Jul 10, 2026
Tracked Since Jul 09, 2026