Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78069— Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6

Quick assessment

Affected
j2commerce.com J2Store extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: Joomla 扩展 - j2commerce.com - J2Store 1.0.0-3.3.21、4.0.0-4.0.21、4.1.0-4.1.6 中 Apps 控制器委托链缺少授权检查 的 委托路径在实例化应用插件控制器时,整个代码路径中均无访问控制列表(ACL)检查。目前该路径仅因 中针对单数形式 ACL 键 的通配符拒绝规则(即由于不存在显式允许规则而生效的通配符拒绝)间接返回 403 错误,而非出于任何刻意设计的检查逻辑。 在该路径背后, 使用受调用方影响的表名且未设置允许列

CVSS 9.5 · Critical EPSS 0.24% · P15

Affected Version Matrix 3

VendorProduct Version RangeStatus
j2commerce.com J2Store extension for Joomla 1.0.0-3.3.21 affected
4.0.0-4.0.21 affected
4.1.0-4.1.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78069

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugin controllers with no ACL check anywhere in the code. It currently returns 403 only as a side effect of `fof.xml`'s wildcard-deny resolving under the singularised ACL key `app`, which has no explicit allow rule — not because of any deliberate check. Behind that path, `applocalizationdata::getInstallerTool()` used a caller-influenced table name with no allow-list, both to select a `#__j2store_*` table for truncation and to build a path to SQL files it then executes — a path-traversal-capable file read/execute.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
j2commerce.com J2Store extension for Joomla 1.0.0-3.3.21 -

II. Public POCs for CVE-2026-78069

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78069

登录查看更多情报信息。

Vendor Pages for CVE-2026-78069 (1)

Same Patch Batch · j2commerce.com · 2026-09-03 · 5 CVEs total

CVE-2026-78064 8.8 HIGH Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `sav
CVE-2026-77999 8.7 HIGH Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to ord
CVE-2026-78065 7.1 HIGH Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated
CVE-2026-78000 5.3 MEDIUM Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.

IV. Related Vulnerabilities

V. Comments for CVE-2026-78069

No comments yet


Leave a comment