What is CVE-2026-56291?
A vulnerability in Balbooa Forms allows unauthenticated users to upload files with dangerous types, potentially enabling executable file uploads. This can lead to full Remote Code Execution (RCE). Immediate update to the latest version is strongly recommended.
Azərbaycanca: Balbooa Forms əlavəsində autentifikasiya olunmamış istifadəçilərə təhlükəli fayl tipi yükləməyə imkan verən zəiflik aşkarlanıb. Bu, icra oluna bilən faylların serverə yüklənməsi ilə tam uzaqdan kod icrasına (RCE) gətirib çıxara bilər. Derhal əlavəni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What dangerous vulnerability was discovered in the Balbooa Forms extension?
CVE-2026-56291 allows unauthenticated users to upload files with dangerous types, which can lead to Remote Code Execution (RCE) on the server.
How to protect against this vulnerability?
To protect against CVE-2026-56291, it is strongly recommended to immediately update the Balbooa Forms extension to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.