---
id: CVE-2026-101112
title: >-
  Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in
  Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an
  integer attachment ID and deletes the matching database row and file
summary: >-
  Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in
  Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an
  integer attachment ID and deletes the matching database row and file. The
  controller veri…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-639
vendor: balbooa.com
product: com_baforms
affected:
  - com_baforms 1.0.0-2.4.3.3
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T17:17:04.913'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101112'
references:
  - url: 'https://www.balbooa.com/'
    label: security@joomla.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T17:41:02.202Z'
---

## Overview

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
