CVE-2026-81568
Received Received - Intake

Arbitrary File Read in J2Store Joomla Extension

Vulnerability report for CVE-2026-81568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Joomla! Project

Description

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concatenating the configured attachment folder with the product file's stored `product_file_save_name`, using only `JPath::clean()` (which normalises separators but does not resolve or reject `..` segments) and a plain `JFile::exists()` check β€” never confirming the resolved path stayed inside the configured attachment folder. If a product file's `product_file_save_name` ever contained a `../` traversal segment β€” most plausibly via the CSRF-forgeable admin product-file save actions described in Issue 1, but equally by any future integration or bug that writes that field β€” any customer holding a valid download `token`/`pid` pair for that product file could have the traversal resolve to a path outside the attachment folder and download any file readable by the web server (e.g. `configuration.php`).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
j2commerce j2store 1.0.0
j2commerce j2store 3.3.2
j2commerce j2store to 4.0.22 (inc)
j2commerce j2store to 4.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an arbitrary file read flaw in the J2Store Joomla extension versions 1.0.0-3.3.2, 4.0.0-4.0.22, and 4.1.0-4.1.7. It allows attackers to read sensitive files on the server by exploiting path traversal via the task=download parameter. The issue occurs because the application does not properly validate file paths, enabling access to files outside the intended directory.

Detection Guidance

Check if J2Store is installed and its version is between 1.0.0-3.3.2, 4.0.0-4.0.22, or 4.1.0-4.1.7. Review product file paths for `product_file_save_name` containing `../` or similar traversal sequences. Inspect web server access logs for suspicious `task=download` requests with token/pid pairs.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to sensitive files such as configuration.php, exposing database credentials, API keys, or other confidential data. Attackers could leverage this to escalate privileges, steal information, or compromise the entire Joomla site.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting personal and health data. Non-compliance may result in legal penalties, fines, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Upgrade J2Store to the latest patched version immediately. Temporarily disable the download feature if an upgrade is not possible. Restrict web server file permissions to limit access to sensitive files like configuration.php.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart