CVE-2026-101112
Received Received - Intake

Unauthorized Attachment Deletion in Balbooa Forms

Vulnerability report for CVE-2026-101112, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Joomla! Project

Description

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
balbooa forms to 2.4.3.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Balbooa Forms for Joomla (versions before 2.4.3.4) allows unauthorized deletion of attachments. The removeTmpAttachment action deletes files and database entries but fails to verify if the attachment belongs to the current user, session, or form. A guest can exploit this by obtaining a session token and deleting any attachment.

Impact Analysis

Attackers could delete critical files or data uploaded by users, leading to data loss or disruption of services. Since no authentication beyond a session token is required, even unauthenticated users could exploit this if they can obtain a token.

Compliance Impact

This vulnerability could violate GDPR or HIPAA by enabling unauthorized deletion of personal or sensitive data, potentially leading to data integrity breaches. Organizations using this extension may fail compliance checks for data protection and access controls.

Mitigation Strategies

Update the Balbooa Forms extension to version 2.4.3.4 or later to patch the vulnerability. Remove any unnecessary temporary attachments or files that may have been exposed. Review system logs for unauthorized deletion attempts or suspicious activity related to attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101112. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart