← Back to Feed

Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

CVE-2026-56291

July 31, 2026 · CISA · Severity: CRITICAL

Balbooa Forms, a popular web form builder, has been identified with a critical vulnerability (CVE-2026-56291) that allows unauthenticated users to upload arbitrary files, including executable files, potentially leading to remote code execution (RCE). This unrestricted upload of dangerous file types poses a severe security risk, as attackers could exploit it to gain full control over affected systems. The Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on July 10, 2026, confirming that it is actively being exploited in the wild. Organizations using Balbooa Forms are at risk of compromise, as attackers could leverage this vulnerability to deploy malware, steal sensitive data, or disrupt operations. The widespread exploitation underscores the urgency for users to apply patches or mitigations provided by Balbooa. Failure to address this vulnerability could result in significant financial, reputational, and operational damage, highlighting the importance of proactive cybersecurity measures in protecting critical systems and data.

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. Vendor: Balbooa Product: Forms CISA Date Added: 2026-07-10 CVE: CVE-2026-56291 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2026-56291 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • The flaw enables remote code execution, allowing attackers to run arbitrary commands on affected systems.
  • CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
  • Balbooa Forms: Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
☕ Buy a Coffee