CVE-2026-101126

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata tampering, and path traversal risks (e.g., via getFilePath())

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    Uploaded filename in Balbooa Forms is stored XSS, rendered in the admin view! CVE-2026-101127 (CVSS 8.6): Anonymous submit, malicious filename, admin opens the submission. Same 2.4.3.4 drop! Two siblings on the attachment path: - CVE-2026-101112 deletes any visitor’s temp attachment. - CVE-2026-101126 rewrites attachment names and references on submit. All five are unauth through a public form. https://mysites.guru/vulnerabilities/CVE-2026-102425/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #XSS #BugBounty

    00031116
    943 followersView on X

Explore more