CVE-2026-67359
8.7j2commerce · J2Store extension for Joomla
The J2Store extension for Joomla contains an authorization bypass vulnerability, allowing unauthenticated remote attackers to access sensitive data through user-controlled keys.
Executive summary
The J2Store extension for Joomla is affected by an authorization bypass vulnerability that could allow unauthenticated attackers to access sensitive information.
Vulnerability
This is an authorization bypass flaw categorized under CWE-639. The vulnerability allows an unauthenticated attacker to manipulate parameters to access data they are not authorized to view.
Business impact
The CVSS score of 8.7 highlights a high risk of unauthorized information disclosure. By exploiting this flaw, an attacker could potentially gain access to customer databases, order history, or other sensitive business records stored within the J2Store extension, leading to severe privacy violations and regulatory non-compliance.
Remediation
Immediate Action: Verify if a patched version has been released by checking the j2commerce website and update the J2Store extension immediately upon availability.
Proactive Monitoring: Review web server and application logs for suspicious access patterns or unexpected parameter values in requests directed toward J2Store components.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block unauthorized access attempts targeting Joomla extensions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Administrators using the J2Store extension should treat this vulnerability as urgent. If a patch is not yet available, consider disabling the extension or restricting access to the affected functionality until a secure version is deployed to mitigate the risk of data exposure.