highOther

CISA KEV Catalog Addition: iCagenda and Balbooa Forms Unrestricted File Upload Vulnerabilities

First seen Jul 11, 2026 · Updated Jul 11, 2026

CISAKEVfile-uploadweb-applicationCMSpluginJoomlaactive-exploitationBOD-26-04

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: an unrestricted file upload flaw in iCagenda (CVE-2026-48939) and a similar flaw in Balbooa Forms (CVE-2026-56291). Both vulnerabilities allow attackers to upload dangerous file types, potentially leading to remote code execution on affected web servers.

Technical Analysis

CVE-2026-48939 and CVE-2026-56291 are classified as Unrestricted Upload of File with Dangerous Type vulnerabilities (CWE-434), commonly found in CMS plugins/extensions such as iCagenda (Joomla event management) and Balbooa Forms. These flaws typically allow an unauthenticated or low-privileged attacker to upload web shells or executable payloads by bypassing file-type validation, resulting in remote code execution on the underlying web server. Given active exploitation confirmed by CISA, threat actors are likely leveraging automated scanning to identify vulnerable installations and deploy backdoors for persistent access. If these compromised web servers host or interface with RAG pipelines, internal APIs, or agent orchestration tools that fetch data from these CMS platforms, attacker-planted web shells could be used to exfiltrate API keys, poison retrieved content, or pivot into agent-connected infrastructure, making this agent-relevant for organizations that integrate CMS-hosted content into LLM/agent workflows.

Affected Systems

iCagenda (Joomla extension) - versions vulnerable to CVE-2026-48939; Balbooa Forms (web form builder/plugin) - versions vulnerable to CVE-2026-56291; any web servers/CMS installations running these unpatched components

Indicators of Compromise

  • No specific hashes, IPs, or domains provided in source data; refer to CISA KEV Catalog and CVE.org records for CVE-2026-48939 and CVE-2026-56291 for updates

Remediation Steps

  1. 1

    Patch affected components

    Update iCagenda and Balbooa Forms plugins to the latest patched versions as soon as vendor fixes are available.

  2. 2

    Review KEV Catalog compliance

    FCEB agencies must remediate per BOD 26-04 timelines; all organizations should prioritize based on exposure and exploitation risk.

  3. 3

    Check for prior compromise

    Audit web server logs and file directories for unauthorized uploaded files, web shells, or unusual file extensions predating the patch.

  4. 4

    Restrict file upload functionality

    Implement strict file-type validation, content-type checks, and sandboxing for any upload features on public-facing web applications.

  5. 5

    Monitor for lateral movement

    If compromised web hosts interact with internal APIs, credential stores, or agent/RAG systems, rotate exposed API keys and audit downstream data access.

CVE / Advisory IDs

CVE-2026-48939CVE-2026-56291

Industries Most Exposed

GovernmentFederal Civilian Executive BranchWeb HostingAny organization using Joomla/iCagenda or Balbooa Forms

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.