Unauthenticated Execution Flaw in Joomla Extension by JoomlaFry
CVE-2026-102779

6.9MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-102779?

A vulnerability exists in the Joomla extension TF Content, where published automation tasks can be executed by unauthenticated users. The extension allows any guest to submit a numeric ID corresponding to published tasks, facilitating immediate execution without proper authentication or access control measures. This absence of verification can lead to unauthorized actions being triggered on the site, potentially compromising its integrity and security.

Affected Version(s)

TF Content for Joomla 2.9.0-2.9.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Rybak
.