CVE-2026-67363
Received Received - Intake

Pre-auth Payment Amount Tampering in Balbooa Forms

Vulnerability report for CVE-2026-67363, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Joomla! Project

Description

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
balbooa forms to 2.4.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
CWE-472 The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a pre-authentication payment amount tampering issue in the Balbooa Forms Joomla extension versions before 2.4.3.2. The stripeCharges and payAuthorize endpoints accept payment amounts from client-controlled parameters without verifying them against the form's configured product prices. This allows unauthenticated attackers to manipulate payment amounts, purchase items for arbitrary prices like $0.01, and forge line items, quantities, and shipping details.

Impact Analysis

If you use the affected Balbooa Forms extension, an attacker could exploit this to pay less than the actual price for products or services, potentially causing financial losses. Since no authentication or CSRF checks are enforced, attackers can manipulate payments without access to user accounts. This could also lead to incorrect order processing and customer disputes.

Compliance Impact

This vulnerability may impact compliance with financial and data protection regulations. For GDPR, improper payment handling could lead to financial data breaches or unauthorized transactions, violating data integrity and confidentiality principles. For HIPAA, if payment data involves protected health information, unauthorized tampering could compromise compliance with security and privacy requirements.

Mitigation Strategies

Update Balbooa Forms to version 2.4.3.2 or later to address the pre-authentication payment tampering vulnerability. Disable or restrict access to the stripeCharges and payAuthorize endpoints if updates are not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67363. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart