Executive brief
A vulnerability in the Tassos Framework Plugin for Joomla allows unauthorized users to delete files on the web server. This could lead to significant website disruption, loss of critical data, or a complete site outage. The plugin is a foundational component used by several popular Joomla extensions, making this a high-impact issue for affected site owners.
Technical details
An improper access control vulnerability (CWE-284) exists in the Tassos Framework Plugin for Joomla. The flaw allows an unauthenticated remote attacker to trigger arbitrary file deletion on the affected site's file system. According to the CVSS 4.0 vector provided by the Joomla! Project, the attack vector is network-based with low complexity and requires no privileges or user interaction. Successful exploitation can lead to a total loss of integrity and availability of the application's data and files. Site administrators should check for updates from the vendor (Tassos Marinos) to mitigate this risk.
Affected products
- Tassos Marinos Tassos Framework Plugin
Timeline
- 2026-05-27: disclosed: CVE-2026-48906 published to the NVD dataset.