CVE-2026-102424
Last modified
CVE-2026-102424 is a high-severity vulnerability rated 8.9/10 on the CVSS scale. Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths.
Description
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102424?
How severe is CVE-2026-102424?
How do I fix CVE-2026-102424?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102399Unauthenticated Cross Site Request Forgery (CSRF) in Photo G…5.4
- CVE-2026-10240A vulnerability was identified in JeecgBoot up to 3.9.2. The…6.3
- CVE-2026-10241A security flaw has been discovered in jeecgboot The server …6.3
- CVE-2026-102414pbkdf2 through 3.1.6 re-hashes passwords longer than the dig…3.7
- CVE-2026-10242A weakness has been identified in itsourcecode Content Manag…6.3
- CVE-2026-102422shell-quote's `quote()` function emits a `{ comment }` token…8.1
- CVE-2026-102425Joomla Extension - balbooa.com - Unauthenticated RCE via fie…9.5
- CVE-2026-102427Joomla Extension - ordasoft.com - Unauthenticated Remote Cod…10
- CVE-2026-10243A security vulnerability has been detected in code-projects …7.3
- CVE-2026-102437OS Command Injection in internal/gitcmd (git diff filter.cle…7.8
- CVE-2026-10244A vulnerability was detected in SourceCodester Pharmacy Sale…3.5
- CVE-2026-10245A flaw has been found in SourceCodester Pharmacy Sales and I…3.5
Are you affected by CVE-2026-102424?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
