CVE-2026-78064: Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6

Published Sep 3, 2026
·
Updated

Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF save task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - fof.xml grants the carts view's tasks a wildcard true ACL, and FOF only enforces CSRF tokens on back-end HTML requests, not on front-end format=raw requests. J2StoreControllerCarts already scoped remove() to the caller's own session, but never overrode the generic FOF save task, so it remained reachable to insert new cart rows with an attacker-chosen userid/sessionid, or overwrite an existing row by id.

Affected Software

1 affected component
J2Store J2Store>=1.0.0<=3.3.21, >=4.0.0<=4.0.21, >=4.1.0<=4.1.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade J2Store (j2commerce.com) to a version that resolves this vulnerability.

    Fixed in 1.0.0-3.3.21
  2. Upgrade

    Upgrade J2Store (j2commerce.com) to a version that resolves this vulnerability.

    Fixed in 4.0.0-4.0.21
  3. Upgrade

    Upgrade J2Store (j2commerce.com) to a version that resolves this vulnerability.

    Fixed in 4.1.0-4.1.6

Event History

Sep 3, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionWeakness

Frequently Asked Questions

1

Does exploitation require an authenticated Joomla or J2Store account?

No. The affected save task is reachable through front-end requests using format=raw, where FOF does not enforce CSRF tokens for this path.

2

Is a custom ACL configuration required for the issue to be reachable?

No custom ACL change is described. The bundled fof.xml grants a wildcard true ACL to tasks in the carts view.

3

What can an attacker change through the exposed task?

An attacker can create cart records with an attacker-chosen user_id and session_id, or overwrite an existing cart record when its ID is known. The controller's session scoping applied to remove(), but not to the inherited save task.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203