Unauthenticated Execution Flaw in Joomla Extension by JoomlaFry
CVE-2026-102779
6.9MEDIUM
What is CVE-2026-102779?
A vulnerability exists in the Joomla extension TF Content, where published automation tasks can be executed by unauthenticated users. The extension allows any guest to submit a numeric ID corresponding to published tasks, facilitating immediate execution without proper authentication or access control measures. This absence of verification can lead to unauthorized actions being triggered on the site, potentially compromising its integrity and security.
Affected Version(s)
TF Content for Joomla 2.9.0-2.9.4
