External risk intelligence

Balbooa Forms RCE via Field Shortcode Injection

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-102425

This vulnerability affects a Joomla form extension that processes public form submissions. Since the vulnerable code is triggered by end-user interaction with web forms, the attack surface is exposed to the public internet by design in normal operation.

Code Injection

Balbooa Forms

before 2.4.3.4

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability impacts Balbooa Forms, a Joomla extension, allowing unauthenticated attackers to execute arbitrary code remotely. The issue stems from how the extension processes user-submitted data within optional PHP code, enabling malicious injection. While exploitation requires specific configurations, its critical severity and potential for remote code execution warrant attention.

  • Unauthenticated attackers can run code remotely.
  • Affects Balbooa Forms for Joomla websites.
  • Confirm if your specific configuration is exposed.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by submitting a specially crafted form, allowing them to execute arbitrary PHP code on the server. This occurs because the system improperly processes user-submitted data within specific shortcodes before executing it as PHP code, bypassing security checks.

  • Public form access required.
  • User-submitted data in specific shortcodes.
  • Unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary PHP code on the server. This could occur when a public form utilizes the optional PHP-after-submission action and includes an attacker-controlled field shortcode within a double-quoted PHP string, which is then processed by `eval()`.

  • Server-side code execution.
  • Exploits vulnerable form submission processing.
  • Leads to unauthorized server compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Balbooa Forms extension for Joomla is susceptible to unauthenticated Remote Code Execution. This vulnerability impacts customers using versions prior to 2.4.3.4, particularly those who have enabled the optional PHP-after-submission action and are interpolating attacker-controlled field shortcodes within PHP strings. The first practical step involves identifying all instances of Balbooa Forms, confirming their public reachability and business criticality, and then locating the accountable owner to plan remediation based on risk.

  • Identify accountable application owners.
  • Verify public-facing form exposures.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Balbooa Forms extension?

Balbooa Forms is a popular plugin designed for the Joomla content management system. It allows website owners to build custom, interactive web forms for collecting visitor data. Administrators often use its advanced features to trigger automated tasks, including executing custom PHP scripts immediately after a user submits a form entry.

What does CWE-94 mean in the context of CVE-2026-102425?

CWE-94 refers to Improper Control of Generation of Code, commonly known as Code Injection. In this vulnerability, the software fails to sanitize data before incorporating it into a command. Because the extension uses an 'eval()' function to process form data, an attacker can manipulate input to force the server to execute malicious, arbitrary instructions instead of just handling form text.

How does an attacker trigger this vulnerability?

To trigger the bug, an attacker submits a crafted form containing malicious strings. The vulnerability only activates if the administrator has specifically enabled the optional 'PHP-after-submission' feature and placed a field shortcode inside a double-quoted PHP string. If this feature is disabled or the code is not structured to interpolate user input into an 'eval()' call, the specific injection vector does not work.

Is my website at risk from this Joomla vulnerability?

According to Halo Surface Signal, this vulnerability is considered highly relevant because it involves forms designed for public interaction. If your Joomla site uses a vulnerable version of the extension and exposes these forms to the internet, your server is directly reachable for exploitation. Internal forms or those not using the specific 'PHP-after-submission' action have a significantly different risk profile.

What are the first steps to secure my server?

Begin by auditing your Joomla environment to identify all active installations of Balbooa Forms. Check your form configurations to see if the 'PHP-after-submission' action is currently in use. Prioritize these specific forms for review, coordinate with your application owners, and prepare to update the extension to version 2.4.3.4 or later as provided by the vendor.

References