SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77999

HIGH · CVSS 8.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the J2Store extension for Joomla, allowing unauthenticated attackers to exploit weaknesses in the PayPal callback handling, leading to order confirmation fraud. The flawed signature verification process and lack of proper payment amount checks enable attackers to manipulate order statuses without valid payments. E-commerce operators using J2Store versions 1.0.0-3.3.21, 4.0.0-4.0.21, and 4.1.0-4.1.6 should prioritize patching this vulnerability to prevent potential financial losses and reputational damage.

CVE
CVE-2026-77999
Severity
HIGH
CVSS
8.7
EPSS
0.25%

Original NVD Description

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made its verification request with `CURLOPT_SSL_VERIFYPEER` disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when `mc_gross` was a positive number; omitting the field from the POST body (`floatval(null) == 0`) skipped the check entirely. Combined with a merchant-configured `receiver_email` and a sequential, enumerable order id read from the `custom` field, an anonymous POST was enough to move a pending order straight to `CONFIRMED` with no payment, or force another customer's pending order to `FAILED`. `paypalv2.php` performed no amount check under any circumstances.