PT-2026-106018 · Unknown · Tf Content

·

CVE-2026-102779

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TF Content versions 2.9.0 through 2.9.4
Description The extension exposes the site task records.custom action without authentication, Access Control List (ACL), Cross-Site Request Forgery (CSRF) protection, task-trigger, content-binding, or cron-token enforcement. This allows an unauthenticated guest to provide the numeric ID of any published TF Content task and force the component to execute its configured executor immediately.
Recommendations Update TF Content to a version later than 2.9.4.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102779

Affected Products

Tf Content