CVE-2026-56291 · Moderate · CISA KEV
Balbooa Forms Unrestricted File Upload Leads to Remote Code Execution
Threat Engine Auto-Feed · data current as of 2026-07-10
CVE-2026-56291 in Balbooa Forms allows unauthenticated attackers to upload dangerous file types, potentially leading to full Remote Code Execution (RCE). This vulnerability is listed in CISA KEV, indicating active exploitation in the wild, despite a low EPSS score. Organizations using Balbooa Forms are at risk of significant compromise.
- CVSS:
- EPSS percentile: 0.19623
- Exploitation pressure: 37/100 (Moderate)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 20th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves an 'unrestricted upload of file with dangerous type' (CWE-434). This means the application does not properly validate or restrict the types of files users can upload. An attacker can exploit this by uploading a file type that the server can execute, such as a script or an executable, rather than a benign file like an image or document.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Any organization using Balbooa Forms, particularly those in Financial Services and Technology sectors due to assessed adversary targeting.
- Organizations with web servers directly exposed to the internet running Balbooa Forms.
Misconfigurations that escalate it
- Web servers configured to execute uploaded files from user-controlled directories.
- Lack of robust input validation and file type filtering on upload functionalities.
High-impact scenarios
- An unauthenticated attacker achieving full Remote Code Execution (RCE) on the server hosting Balbooa Forms.
- Data theft, system compromise, or deployment of further malware (e.g., ransomware) following initial RCE.
- Supply chain compromise or espionage if the affected system is part of a larger development or service delivery pipeline.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor web server logs for unusual file uploads, especially executable or script file types in user-upload directories.
- Implement file integrity monitoring on web server directories to detect unauthorized file changes or additions.
- Scan web applications for known vulnerabilities, specifically looking for CVE-2026-56291.
Contain
- Isolate affected Balbooa Forms instances from the network to prevent further lateral movement.
- Disable or restrict upload functionalities within Balbooa Forms if immediate patching is not feasible.
- Review and revoke any unauthorized user accounts or changes made post-compromise.
Patch
- Apply the latest security patches or updates provided by Balbooa for Forms to address CVE-2026-56291 as soon as they become available.
Frontier verdict — Moderate
High priority due to active exploitation (CISA KEV) and potential for unauthenticated RCE, especially for organizations in targeted sectors.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.