CVE-2026-56291CISA KEVEPSS p96.6%

CVE-2026-56291Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa / Forms

Description

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.85% probability of exploitation · percentile 96.6% · 2026-10-05T12:00:23Z
Last modified2026-07-24

CISA KEV entry

Added to KEV: 2026-07-10

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.