Authorization Flaw in J2Store Plugin by Joomla Extension
CVE-2026-78069

9.5CRITICAL

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-78069?

The J2Store plugin for Joomla contains an authorization vulnerability that arises from inadequate access controls in the Apps controller delegation chain. Certain versions allow the J2StoreControllerApps's appTask function to instantiate app-plugin controllers without any access control list (ACL) checks. This leads to potential exploitation whereby unauthorized users may execute operations that can modify or truncate database tables and read sensitive files on the server. The vulnerability is particularly concerning due to the reliance on an implicit denial method in ACL configurations that does not provide explicit security measures, creating an opportunity for attackers to perform unauthorized actions.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.21

J2Store extension for Joomla 4.0.0-4.0.21

J2Store extension for Joomla 4.1.0-4.1.6

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.