Description
Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of any published TF Content task and make the component dispatch its configured executor immediately.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated execution of extension automation tasks
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated guest can invoke the TF Content extension’s records.custom_action endpoint by supplying the numeric ID of a published task, causing the component to immediately dispatch its configured executor. This allows an attacker to trigger any task configured by the site administrator without authentication, potentially executing arbitrary actions defined in that task.

Affected Systems

The vulnerability affects joomlafry.com’s TF Content for Joomla extensions, specifically the 2.9.0 through 2.9.4 releases.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack paths require no authentication or special permissions beyond supplying a numeric ID, which is inferred from the description to be trivial to launch from a web browser. Consequently, the likelihood of exploitation is high for any publicly accessible site that remains unpatched.

Generated by OpenCVE AI on October 5, 2026 at 18:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade TF Content to a version that enforces authentication and proper ACL checks on the records.custom_action task.
  • If an upgrade cannot be performed immediately, block unauthenticated access to the records.custom_action endpoint by configuring Joomla ACL rules or adjusting the web server to deny those requests.
  • Deploy a web application firewall rule that detects and blocks requests to records.custom_action containing numeric task IDs without an accompanying CSRF token or authenticated session.

Generated by OpenCVE AI on October 5, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of any published TF Content task and make the component dispatch its configured executor immediately.
Title Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-10-05T19:02:58.629Z

Reserved: 2026-09-29T16:46:15.044Z

Link: CVE-2026-102779

cve-icon Vulnrichment

Updated: 2026-10-05T19:02:54.871Z

cve-icon NVD

Status : Received

Published: 2026-10-05T17:17:10.040

Modified: 2026-10-05T20:17:07.750

Link: CVE-2026-102779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:45:19Z

Weaknesses