What is CVE-2026-65880?
CVE-2026-65880 is an unauthenticated remote code execution vulnerability in the Balbooa Forms extension for Joomla, affecting versions below 2.4.3. It stems from insecure processing logic for forms containing a signature field type. Users must immediately update to version 2.4.3 or later to mitigate the risk.
Azərbaycanca: CVE-2026-65880, Joomla üçün Balbooa Forms əlavəsində (<2.4.3) autentifikasiya olmadan uzaqdan kod icrasına (RCE) imkan verir. Zəiflik imza sahəsi tipli formaların işlənmə məntiqindəki təhlükəsizlik boşluğundan qaynaqlanır. İstifadəçilər dərhal 2.4.3 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: balbooa.com
FAQ2
Which Joomla extension is affected by CVE-2026-65880 and what does the vulnerability allow?
CVE-2026-65880 affects the Balbooa Forms extension for Joomla. This vulnerability allows unauthenticated remote code execution (RCE).
How should CVE-2026-65880 be mitigated?
Users must immediately update the Balbooa Forms extension to version 2.4.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.