CVE-2026-82190
Received Received - Intake

Predictable Order Access Token in J2Store Joomla Extension

Vulnerability report for CVE-2026-82190, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Joomla! Project

Description

Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining guest access to that order's details and any purchased digital downloads. Because the token is never rotated, this exposure persists indefinitely even after the underlying secret-disclosure vector is patched, unless the Joomla secret itself is also rotated. The attack complexity (`AC:H`) is high because it depends on the secret already being known through a separate vector; it is not directly exploitable by an anonymous visitor with no other foothold.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
j2commerce j2store From 1.0.0 (inc) to 3.3.2 (inc)
j2commerce j2store From 4.0.0 (inc) to 4.0.22 (inc)
j2commerce j2store From 4.1.0 (inc) to 4.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1241 The device uses an algorithm that is predictable and generates a pseudo-random number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects J2Store, a Joomla extension, allowing anyone with knowledge of the site's Joomla secret to generate a valid access token for any order. This grants unauthorized access to order details and digital downloads without placing an order. The token remains valid indefinitely unless the Joomla secret is rotated.

Detection Guidance

This vulnerability requires knowledge of the Joomla site's secret key to compute order access tokens. Detection involves checking for unauthorized access to order details or digital downloads without valid user credentials. Review server logs for unusual access patterns to order endpoints or download requests.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized access to sensitive order information and digital products. Attackers could view or download purchased items without authorization, potentially leading to data breaches or financial loss.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by exposing personal and sensitive order data to unauthorized parties. Compliance may be compromised due to unauthorized access to protected information.

Mitigation Strategies

Rotate the Joomla secret key immediately to invalidate all previously computed access tokens. Update J2Store to the latest patched version (1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 or later). Audit all orders for unauthorized access and revoke any suspicious digital downloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82190. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart