Description
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Order State Manipulation
Action: Patch Immediately
AI Analysis

Impact

Any order unauthenticated denial‑of‑service against the order processing pipeline. The flaw allows attackers to mass‑fail pending orders, disrupting revenue and forcing manual reprocessing, or to flip already‑fulfilled orders back to FAILED, creating operational confusion, unwarranted refunds or cancellations and increased customer‑support workload.

Affected Systems

The vulnerability affects the J2Store extension for Joomla from j2commerce.com, covering all releases from 1.0.0 to 3.3.2, 4.0.0 to 4.0.22, and 4.1.0 to 4.1.7. Systems running these versions should be reviewed for potential exploitation.

Risk and Exploitability

With a the issue is High, and the% indicates a very low exploitation probability, though the lack of a KEV listing does not diminish its seriousness. The attack vector is unauthenticated; any user who can reach the order interface can manipulate the status of orders. No privileges or sensitive data are required beyond the ability to invoke the order status change operation.

Generated by OpenCVE AI on September 17, 2026 at 08:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade J2Store to version 4.1.8 or later where the status change validation is fixed.
  • If an upgrade cannot be performed immediately, restrict access to the order management interface so that only authenticated administrator accounts can change order status and disable the direct status‑change URL parameter.
  • Implement monitoring of order status changes, logging anomalies, and review failed orders to detect any unauthorized changes promptly.

Generated by OpenCVE AI on September 17, 2026 at 08:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared J2commerce.com
J2commerce.com j2store Extension For Joomla
Vendors & Products J2commerce.com
J2commerce.com j2store Extension For Joomla

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
Title Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
Weaknesses CWE-472
CWE-602
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

J2commerce.com J2store Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-16T05:58:09.413Z

Reserved: 2026-08-28T07:50:54.878Z

Link: CVE-2026-82189

cve-icon Vulnrichment

Updated: 2026-09-15T19:28:09.207Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T19:17:41.980

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-82189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:15:07Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter

  • CWE-602

    Client-Side Enforcement of Server-Side Security