CVE-2026-82189: CWE-472: External Control of Assumed-Immutable Web Parameter in j2commerce.com J2Store extension for Joomla
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
AI Analysis
Technical Summary
CVE-2026-82189 is an external control of an assumed-immutable web parameter vulnerability (CWE-472) in the J2Store extension for Joomla. It allows unauthenticated attackers to mark any order as Failed without providing correct payment or transaction data. This can be exploited to perform denial-of-service attacks on the order pipeline by mass-failing pending orders or flipping fulfilled orders back to Failed, disrupting business operations and customer support processes. The vulnerability affects multiple version ranges of J2Store and does not require authentication or valid transaction details to exploit.
Potential Impact
The vulnerability enables unauthenticated attackers to disrupt the order processing workflow by marking orders as Failed. This can lead to denial-of-service conditions against the order pipeline, revenue disruption due to mass-failing of pending orders, and operational confusion from flipping fulfilled orders back to Failed. The latter may cause unwarranted refunds, cancellations, and increased customer support load. No authentication or valid payment data is required, increasing the attack surface and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor for unusual order status changes and consider implementing additional access controls or validation on order status updates to mitigate unauthorized modifications.
CVE-2026-82189: CWE-472: External Control of Assumed-Immutable Web Parameter in j2commerce.com J2Store extension for Joomla
Description
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
CVSS v4.0
Score 8.7high
Affected software
j2commerce.com
J2Store extension for Joomla
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-82189 is an external control of an assumed-immutable web parameter vulnerability (CWE-472) in the J2Store extension for Joomla. It allows unauthenticated attackers to mark any order as Failed without providing correct payment or transaction data. This can be exploited to perform denial-of-service attacks on the order pipeline by mass-failing pending orders or flipping fulfilled orders back to Failed, disrupting business operations and customer support processes. The vulnerability affects multiple version ranges of J2Store and does not require authentication or valid transaction details to exploit.
Potential Impact
The vulnerability enables unauthenticated attackers to disrupt the order processing workflow by marking orders as Failed. This can lead to denial-of-service conditions against the order pipeline, revenue disruption due to mass-failing of pending orders, and operational confusion from flipping fulfilled orders back to Failed. The latter may cause unwarranted refunds, cancellations, and increased customer support load. No authentication or valid payment data is required, increasing the attack surface and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor for unusual order status changes and consider implementing additional access controls or validation on order status updates to mitigate unauthorized modifications.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-08-28T07:50:54.878Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa9963d55bf5e2cf53fe843
Added to database: 09/15/2026, 19:02:21 UTC
Last enriched: 09/15/2026, 19:16:28 UTC
Last updated: 09/16/2026, 03:17:55 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.