Authorization Flaw in J2Store Plugin by Joomla Extension
CVE-2026-78069
What is CVE-2026-78069?
The J2Store plugin for Joomla contains an authorization vulnerability that arises from inadequate access controls in the Apps controller delegation chain. Certain versions allow the J2StoreControllerApps's appTask function to instantiate app-plugin controllers without any access control list (ACL) checks. This leads to potential exploitation whereby unauthorized users may execute operations that can modify or truncate database tables and read sensitive files on the server. The vulnerability is particularly concerning due to the reliance on an implicit denial method in ACL configurations that does not provide explicit security measures, creating an opportunity for attackers to perform unauthorized actions.
Affected Version(s)
J2Store extension for Joomla 1.0.0-3.3.21
J2Store extension for Joomla 4.0.0-4.0.21
J2Store extension for Joomla 4.1.0-4.1.6
