File Metadata Tampering Risk in Balbooa Forms by Balbooa
CVE-2026-101126

6.9MEDIUM

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-101126?

The vulnerability in Balbooa Forms allows attackers to exploit the final form submission process that handles JSON arrays per upload field. This process inadequately checks the client-supplied filenames and display names, which can lead to severe security risks such as cross-session claiming and metadata tampering. Additionally, the lack of stringent validation allows potential path traversal attacks, making it crucial for users of affected versions to apply necessary updates and patches promptly.

Affected Version(s)

Balbooa Forms extension for Joomla 1.0.0-2.4.3.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergiy Tryzhychynskyi
.