POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
← Blog

Balbooa Forms RCE (CVE-2026-102425): Field Shortcodes, eval(), and AT:P Reality

Admin · September 30, 2026 · 32 views

Why CVE-2026-102425 is not “another Joomla plugin CVE”

Balbooa Forms (com_baforms) is a commercial-grade form builder used on thousands of Joomla storefronts and lead-gen sites. CVE-2026-102425 (Joomla! Project CNA, CVSS 4.0 9.5 Critical) is unauthenticated remote code execution when three conditions align:

  1. Extension version < 2.4.3.4 (fixed in 2.4.3.4+; vendors recommend 2.4.1 clean install).
  2. A public form enables PHP-after-submission processing.
  3. That PHP embeds a field shortcode inside a double-quoted PHP string, so attacker-controlled submit values break out of the string before eval() runs.

CVSS AT:P (Attack Requirements: Present) matters for prioritization: installing the module is not enough—a dangerous admin configuration must exist. That does not mean you can ignore it; it means your runbook must include form configuration review, not only version checks.

Mechanism write-up and authorized lab tooling: CVE-2026-102425 on pocbit.org. Upstream repository: murrez/CVE-2026-102425.

How field shortcodes become code injection

Balbooa lets site owners run custom PHP after a visitor submits a form. That PHP can reference field shortcodes—placeholders replaced with the raw submitted value before execution.

When those values land inside double-quoted PHP without strict allow-listing, classic injection applies: a payload such as ";echo marker;// closes the string, runs attacker code, and comments out the remainder. The component then eval() the resulting string—CWE-94 code injection with network reachability and no login.

This is distinct from CVE-2026-67364 (URL [parameter=X] shortcode class, fixed 2.4.3.2). Conflating them wastes patch verification time.

Same release train on com_baforms also saw CVE-2026-102424, CVE-2026-101127, CVE-2026-101112, and CVE-2026-101126—treat Balbooa updates as a bundle, not a single CVE checkbox.

Defender checklist

| # | Action | Detail | |---|--------|--------| | 1 | Inventory Balbooa Forms version | administrator/components/com_baforms manifest or Module Manager | | 2 | Upgrade to ≥ 2.4.3.4 | Vendor guidance: uninstall with delete module files, reinstall 2.4.1+ if files were stale | | 3 | Audit every public form | Remove PHP-after-submit actions until patched; note forms with field shortcodes in quoted strings | | 4 | Enable reCAPTCHA on public submits | Reduces spray; not a substitute for patch | | 5 | Scan images/baforms/uploads/ and module dir for unexpected .php | Post-incident hygiene | | 6 | Correlate WAF logs | option=com_baforms, task=form.message, loadAjaxForm |

Cross-read: Joomla security checklist (2026), Joomla extensions basics, RCE vs local privilege escalation.

HTTP surface defenders should recognize

Modern Balbooa on Joomla 4+ commonly uses:

| Step | Typical request | |------|-----------------| | Load form HTML/AJAX | GET index.php?option=com_baforms&task=form.loadAjaxForm&id=N | | Submit | POST to form action with task=form.message, form-id, field names |

Avoid assuming format=json on front-end tasks—many sites return broken controller JSON. Legacy installs may still expose view=form&form_id=N or form.submitForm.

Blue teams can hunt edge logs for POST bursts to com_baforms with odd field values containing ";, eval, or file_put_contents fragments—often paired with 500 errors on misconfigured shops.

Detection and asset discovery (authorized inventory only)

Passive discovery strings (FOFA/Shodan-style) help you find your estates:

body="com_baforms" || body="/components/com_baforms/"
body="balbooa" && body="option=com_baforms"

Version hints may appear in /components/com_baforms/config.xml when exposed—use results to open tickets, not to probe third parties.

Watch CVE Detector for new Balbooa-class signals; when pocbit publishes a PoC, map the CVE to your installed version before scanners arrive.

Patch validation in a lab

Authorized teams should:

  1. Clone a Joomla 4/5 VM with Balbooa < 2.4.3.4 and a public form configured with vulnerable PHP-after-submit (vendor test docs or isolated admin setup).
  2. Run check/exploit tooling from the public PoC page or GitHub repo in check mode first.
  3. Upgrade to 2.4.3.4+, repeat—expect patched_version or failed exploitation.
  4. Document evidence for change management.

See safe PoC lab setup and step-by-step CVE PoC testing.

FAQ

We do not use PHP-after-submit—are we safe?

You are lower risk on AT:P, but still upgrade. Admins may enable dangerous actions later; old feed.php-style surprises often come from forgotten forms.

Can WAF block this permanently?

Temporary virtual patches on form.message parameters help during maintenance windows. Vendor fix removes the root unsafe substitution + eval() pattern.

Does disabling the component help?

Disabling public forms reduces exposure but leaves dormant code on disk. Prefer supported upgrade with file deletion per vendor uninstall guidance.

Bottom line

CVE-2026-102425 is a lesson in admin-defined code paths: any feature that eval() user-influenced text is a future incident. Name the extension version, audit form actions, patch Balbooa on a schedule you can defend—and use public PoCs only in labs you own.