CVE-2026-102424

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    Same forms plugin will email you configuration.php as an auto-reply attachment in Balbooa Forms!! CVE-2026-102424 (CVSS 8.9): Path traversal on the attachment the auto-reply sends! No login, if the form attaches uploads in the reply. Pair it with 102425 and the database password is in your inbox before the shell even lands. Rotate that password after you patch. Fixed in 2.4.3.4. https://mysites.guru/blog/balbooa-forms-2-4-3-4-security-fixes/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #LFI #AppSec

    00021156
    943 followersView on X

Explore more