CVE-2026-56291 is a critical RCE vulnerability in Balbooa Forms (< 2.4.1) for Joomla. Actively exploited and carries a 9.8 CVSS score.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| forms | * | 2.4.1 | vulnerable |
Download and install the latest security update provided by Balbooa. Ensure the Forms extension is updated to version 2.4.1 or higher to resolve the insecure file upload logic.
Identify all Joomla installations running Balbooa Forms versions prior to 2.4.1. Use a centralized management tool or manual audit to ensure every instance is patched across production and staging environments.
Implement a Web Application Firewall (WAF) with rules to block suspicious POST requests to the Forms component. Limit access to the Joomla administrator directory and restrict file upload permissions on the web server to prevent execution in upload directories.
Review web server access logs for unusual POST requests to the Balbooa Forms directory. Inspect the server for unauthorized PHP files or web shells in the media and component folders, and monitor for unexpected outbound network connections.
"Monitor web server logs for POST requests directed at the Balbooa Forms component from unknown IP addresses, especially those followed by immediate access to newly created .php files in upload directories. Use File Integrity Monitoring (FIM) to alert on new executable files within the Joomla /components/com_baforms/ or /media/ paths. Look for common web shell signatures and unexpected system-level processes initiated by the web server user."
Experience superior visibility and a simpler approach to cyber risk management