Skip to content
COOEY

EXPOSURES › CVE-2026-56291

CVE-2026-56291

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-56291 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedransomwaresupply-chainzero-day

Balbooa Forms allows unauthenticated arbitrary file upload leading to full RCE.

This vulnerability enables unauthenticated attackers to upload executable files to Balbooa Forms, resulting in full remote code execution. DIB organizations must ensure no unauthenticated upload endpoints exist in their supply chain to prevent ransomware or data exfiltration via compromised vendor services.

Shame score — Unauthenticated RCE via file upload is a critical, avoidable supply-chain failure that directly violates FedRAMP and CMMC requirements for secure upload mechanisms.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.