CVE-2026-102424
Received Received - Intake

Unauthenticated Path Traversal in Balbooa Forms Joomla Extension

Vulnerability report for CVE-2026-102424, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Joomla! Project

Description

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal β€œauto reply” and β€œattach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
balbooa forms to 2.4.3.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated path traversal vulnerability in the Balbooa Forms Joomla extension versions before 2.4.3.4. It allows attackers to exfiltrate local files by submitting a crafted form with a traversal filename like ../../../../configuration.php. The component trusts user-controlled input and sends the file as an email attachment if auto-reply is enabled.

Impact Analysis

An attacker could access sensitive files on your server such as configuration files, database credentials, or other confidential data. This could lead to complete system compromise, data theft, or further attacks against your Joomla installation or hosting environment.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face regulatory fines and legal consequences if this vulnerability results in data breaches.

Mitigation Strategies

Immediately update Balbooa Forms to version 2.4.3.4 or later to patch the vulnerability. Disable the auto-reply and attach uploaded files options in the Joomla component settings until the update is applied. Review server logs for suspicious file access patterns or unauthorized file attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102424. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart