Skip to main content

CVE-2026-82189: CWE-472: External Control of Assumed-Immutable Web Parameter in j2commerce.com J2Store extension for Joomla

0
High
Published: 09/15/2026 (09/15/2026, 21:31:22 UTC)
Source: CVE Database V5
Vendor/Project: j2commerce.com
Product: J2Store extension for Joomla

Description

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

j2commerce.com

J2Store extension for Joomla

Affected versions
=1.0.0-3.3.22=4.0.0-4.0.22=4.1.0-4.1.7

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 19:16:28 UTC

Technical Analysis

CVE-2026-82189 is an external control of an assumed-immutable web parameter vulnerability (CWE-472) in the J2Store extension for Joomla. It allows unauthenticated attackers to mark any order as Failed without providing correct payment or transaction data. This can be exploited to perform denial-of-service attacks on the order pipeline by mass-failing pending orders or flipping fulfilled orders back to Failed, disrupting business operations and customer support processes. The vulnerability affects multiple version ranges of J2Store and does not require authentication or valid transaction details to exploit.

Potential Impact

The vulnerability enables unauthenticated attackers to disrupt the order processing workflow by marking orders as Failed. This can lead to denial-of-service conditions against the order pipeline, revenue disruption due to mass-failing of pending orders, and operational confusion from flipping fulfilled orders back to Failed. The latter may cause unwarranted refunds, cancellations, and increased customer support load. No authentication or valid payment data is required, increasing the attack surface and ease of exploitation.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, monitor for unusual order status changes and consider implementing additional access controls or validation on order status updates to mitigate unauthorized modifications.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Joomla
Date Reserved
2026-08-28T07:50:54.878Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aa9963d55bf5e2cf53fe843

Added to database: 09/15/2026, 19:02:21 UTC

Last enriched: 09/15/2026, 19:16:28 UTC

Last updated: 09/16/2026, 03:17:55 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses