CVE-2026-67364

10.0

balbooa.com · Balbooa Forms extension for Joomla

The Balbooa Forms extension for Joomla is vulnerable to pre-authentication PHP code injection via an unescaped query parameter, allowing unauthenticated attackers to execute arbitrary code.

Executive summary

The Balbooa Forms extension for Joomla is susceptible to unauthenticated remote code execution, posing a critical threat to server security.

Vulnerability

The extension uses an unsafe eval() call to process custom-PHP handlers. An unauthenticated attacker can inject arbitrary PHP code through query parameters, as the necessary CSRF tokens are leaked independently, rendering them ineffective as a security measure.

Business impact

The ability to execute arbitrary PHP code on the server results in a total compromise of the web application and the underlying server environment. Given the CVSS score of 10.0, the impact includes full data exfiltration, unauthorized administrative actions, and the potential for lateral movement within the network.

Remediation

Immediate Action: Update the Balbooa Forms extension to version 2.4.3.2 or higher.

Proactive Monitoring: Monitor server logs for unexpected PHP executions or suspicious requests directed at the forms extension endpoints.

Compensating Controls: If patching is delayed, ensure reCAPTCHA is enabled on all forms and restrict access to the form builder interface to trusted administrative IP addresses.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical security risk that can be exploited by any remote attacker without authentication. Administrators must prioritize updating the Balbooa Forms extension immediately to prevent unauthorized code execution and maintain the security of the Joomla environment.

More balbooa.com CVEs