Joomla · Balbooa Forms · CVE-2026-101112
**Name of the Vulnerable Software and Affected Versions**
Balbooa Forms versions prior to 2.4.3.4
**Description**
An issue exists where the public `removeTmpAttachment` action allows the deletion of database rows and files by accepting an integer attachment ID. While the controller verifies a Joomla session token to prevent Cross-Site Request Forgery (CSRF)—a type of attack that forces an authenticated user to execute unwanted actions—the model fails to authorize the target object. It does not bind the attachment ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state, allowing any guest with a valid session token to delete attachments.
**Recommendations**
Update to version 2.4.3.4 or later.