Junglewise Threat Intelligence

CVE-2026-65880: Balbooa Forms remote code execution in signature field

CVE-2026-65880 · Severity: info · CVSS 10 · Published 2026-07-28

Executive brief

A critical vulnerability exists in Balbooa Forms, a popular form-building extension for the Joomla content management system. If a form uses the 'signature' field type, an attacker can remotely execute malicious code on the web server without needing to log in. This could lead to a total takeover of the website, theft of customer data, or the installation of ransomware.

Technical details

A remote code execution (RCE) vulnerability exists in Balbooa Forms versions prior to 2.4.3 due to insecure form processing logic. The flaw is specifically located in the handling of the 'signature' field type, which allows for code injection (CWE-94). An unauthenticated remote attacker can exploit this by submitting a specially crafted request to a form containing a signature field. Successful exploitation allows for full system compromise with the privileges of the web server user. The issue is addressed in version 2.4.3.

Affected products

  • Balbooa.com Balbooa Forms 1.0.0 - 2.4.2.1

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References