CVE-2026-82189
Received Received - Intake

Unauthenticated Denial-of-Service in J2Store Joomla Extension

Vulnerability report for CVE-2026-82189, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Joomla! Project

Description

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
j2commerce j2store From 1.0.0 (inc) to 3.3.2 (inc)
j2commerce j2store From 4.0.0 (inc) to 4.0.22 (inc)
j2commerce j2store From 4.1.0 (inc) to 4.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
CWE-472 The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated users to mark any order as 'Failed' in J2Store versions 1.0.0-3.3.2, 4.0.0-4.0.22, and 4.1.0-4.1.7. It disrupts the order pipeline by mass-failing pending orders or reverting already-fulfilled orders to 'Failed', causing revenue loss, operational confusion, and manual reprocessing overhead.

Detection Guidance

This vulnerability allows unauthenticated users to mark orders as failed in J2Store versions 1.0.0-3.3.2, 4.0.0-4.0.22, and 4.1.0-4.1.7. Detection requires checking for unusual order status changes or failed orders without valid reasons. Review Joomla admin logs for mass order status updates to 'Failed' by unknown users. Check database for unexpected order status modifications.

Impact Analysis

If exploited, this vulnerability can lead to financial losses from unwarranted refunds or cancellations, increased customer-support workload, operational disruptions from manual order reprocessing, and reputational damage due to order fulfillment errors.

Compliance Impact

This vulnerability enables unauthorized denial-of-service attacks against order processing, which could lead to unwarranted refunds, cancellations, or operational disruptions. Such actions may violate data integrity and availability requirements under GDPR and HIPAA, potentially resulting in compliance breaches due to unauthorized modifications of transaction records.

Mitigation Strategies

Update J2Store to the latest patched version immediately. If updating is not possible, disable the J2Store extension temporarily. Monitor order statuses for unauthorized changes and review access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82189. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart