CVE-2026-67360
Received Received - Intake

Cross-Site Request Forgery in J2Store Extension

Vulnerability report for CVE-2026-67360, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Joomla! Project

Description

Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
j2commerce j2store From 1.0.0 (inc) to 3.3.20 (inc)
j2commerce j2store From 4.0.0 (inc) to 4.0.20 (inc)
j2commerce j2store From 4.1.0 (inc) to 4.1.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the J2Store Joomla extension versions 1.0.0-3.3.20, 4.0.0-4.0.20, and 4.1.0-4.1.5. An authenticated attacker can exploit it by providing another customer's order ID to copy their cart contents and address data into the attacker's session. The issue occurs because the CSRF token is validated but ownership of the order is not checked.

Detection Guidance

This vulnerability involves an authenticated user exploiting order_id parameters to access another customer's cart data. To detect it, monitor for unusual order_id values in requests, check for repeated CSRF token validations without proper ownership checks, and review logs for cross-customer data access attempts.

Impact Analysis

An attacker could steal sensitive customer data such as order contents and shipping addresses by manipulating order IDs. This could lead to privacy breaches, financial fraud, or identity theft for affected customers.

Compliance Impact

This vulnerability could lead to violations of GDPR due to unauthorized access to personal data and potential data breaches. For HIPAA, if health-related order data is exposed, it may also result in compliance failures.

Mitigation Strategies

Update J2Store to the latest patched version immediately. If updating is not possible, disable the J2Store extension until a patch is applied. Review server logs for suspicious order_id manipulation attempts or unauthorized cart modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67360. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart