Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Balbooa Forms fixes two unauthenticated RCE flaws

Joomla administrators using com_baforms should update to version 2.4.3 or later after two unauthenticated remote code execution flaws were disclosed in Balbooa Forms.

mySites.guru reported that Balbooa Forms versions through 2.4.0 allowed anonymous visitors to upload executable files through a frontend attachment handler. The file-upload issue, classified as CWE-434 and tracked as CVE-2026-56291, could lead to unauthenticated remote code execution and was being exploited in the wild before the vendor issued a fix in 2.4.1.

A separate vulnerability was later identified in the Signature field. CVE-2026-65880 is another unauthenticated RCE and carries a CVSS score of 10.0. It affects versions through 2.4.2.1, meaning that installations updated only to 2.4.1 or 2.4.2 remain exposed. Balbooa fixed this issue in 2.4.3.

  • Update every Balbooa Forms installation to 2.4.3 or later immediately.
  • Review affected sites for unexpected PHP files and administrator accounts.
  • No public proof of concept has been released, but the first flaw is under active exploitation.

Administrators should treat the update as urgent, particularly where the component was reachable from public forms.

Originally reported by mySites.guru.