CVE-2026-82189: Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to FAILED to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is unauthenticated and does not require a correct payment amount, transaction data, or other valid payment information.
Are orders that have already been fulfilled also at risk?
Yes. An attacker can reportedly change already-fulfilled orders back to FAILED, which can create operational confusion and lead to unwarranted refunds or cancellations.