11 July 2026
Reference: CVE-2026-56291
1. What is being reported?
The Balbooa Forms extension for Joomla has a vulnerability that lets anyone upload dangerous executable files without needing to log in. This can let attackers run malicious code on your website, which could lead to complete takeover of the site.
2. What this means in plain English
If your website uses this extension, attackers could gain control, steal data, or disrupt your online services. This risk is serious for any organisation using Balbooa Forms, as it could lead to loss of trust, data breaches, or downtime.
3. Could this affect a small business?
Small businesses, charities, clubs, or any organisation using Joomla with the Balbooa Forms extension could be affected. If you do not use Joomla or this specific extension, you are unlikely to be impacted.
4. What to do now
- Check if your website uses the Balbooa Forms extension for Joomla.
- Contact your IT provider or website manager immediately to apply any available security updates or mitigations from the vendor.
- If no fix is available, consider disabling or removing the extension until it is safe to use.
- Review your website’s exposure to the internet and ensure you follow best practices for patching and security.
5. Ask your IT provider
Can you confirm if our Joomla website uses the Balbooa Forms extension, and if so, have you applied the latest security updates or mitigations for CVE-2026-56291?
6. Bottom line
If you use Balbooa Forms on Joomla, act quickly to secure your website against this critical vulnerability.
Information based on CISA KEV, NVD and reputable security reporting.