CVE-2026-82189

Summary

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to FAILED to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.

Affected Software

VendorProductVersion RangeStatus
j2commerce.comJ2Store extension for Joomla1.0.0-3.3.22affected
j2commerce.comJ2Store extension for Joomla4.0.0-4.0.22affected
j2commerce.comJ2Store extension for Joomla4.1.0-4.1.7affected

Weaknesses

  • CWE-472: CWE-472: External Control of Assumed-Immutable Web Parameter
  • CWE-602: CWE-602: Client-Side Enforcement of Server-Side Security

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References