Anonymous Cart-Record Tampering in J2Store by Joomla Extension
CVE-2026-78064

8.8HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-78064?

The vulnerability presents an access control issue within the J2Store Joomla extension, allowing unauthorized users to tamper with cart records. Through a flawed implementation of the FOF save task, an attacker can exploit a wildcard ACL setting that grants unrestricted access to modify cart entries. This oversight enables the insertion of cart rows with arbitrary user identifiers and session details or the alteration of existing entries by their IDs. Notably, the vulnerability only enforces CSRF protections on backend requests, making it easier for attackers to manipulate cart data through frontend interactions.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.21

J2Store extension for Joomla 4.0.0-4.0.21

J2Store extension for Joomla 4.1.0-4.1.6

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.