Security
Loading…

CVE-2026-56291

CRITICALCVSS 9.8Known Exploited
Description

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

Timeline
Published:July 9th, 2026 11:16 AM
Last modified:July 11th, 2026 5:16 AM
Added to KEV:July 10th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

balbooa

Products

forms
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute