Predictable Token Vulnerability in J2Store Joomla Extension
CVE-2026-82190

6.3MEDIUM

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-82190?

The J2Store extension for Joomla is affected by a vulnerability that allows an attacker to generate valid access tokens for any order using a leaked site secret. This means unauthorized users can access sensitive order details and any associated digital downloads without having previously placed an order. The vulnerability persists indefinitely since the token is not rotated, creating ongoing exposure even if the original breach is remediated. The importance of rotating the Joomla secret is underscored to mitigate this risk.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.22

J2Store extension for Joomla 4.0.0-4.0.22

J2Store extension for Joomla 4.1.0-4.1.7

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.