Unauthenticated Denial of Service in J2Store by j2commerce.com
CVE-2026-82189

8.7HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-82189?

The vulnerability in J2Store allows any user to mark any pending order as Failed without authentication. This can significantly disrupt the order pipeline by enabling mass-failure of pending orders, impacting revenue streams and forcing manual reprocessing. Moreover, existing fulfilled orders can be incorrectly reverted to a Failed status, leading to operational confusion, unnecessary refunds, cancellations, and increased customer support demands. The exploit does not necessitate the correct payment amount or transaction data, presenting a severe risk for businesses relying on the J2Store extension.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.22

J2Store extension for Joomla 4.0.0-4.0.22

J2Store extension for Joomla 4.1.0-4.1.7

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.