CVE-2026-56291
CRITICAL CISA KEVCVSS v3.1: 9.8 · EPSS: 0.0084 (53.5 percentile) · CISA KEV: Yes
Source data as of:
At a glance
- Severity
- CRITICAL
- CVSS
- 9.8 v3.1 · NVD
- EPSS
- 0.0084 (53.5 percentile) · FIRST.org
- CISA KEV
- Yes KEV added: 2026-07-10
- Type
- Unrestricted Upload · NVD CWE
- Attack conditions (CVSS vector)
- NetworkNo privilegesNo user interaction · Source: NVD Vector
- Affected vendors
- balbooa
- Published
- 2026-07-09 · Modified: 2026-07-11
- References
- Jump to references (3)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.