SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82189

HIGH · CVSS 8.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The J2Store extension for Joomla is vulnerable to an unauthenticated denial-of-service attack, allowing any user to mark any order as failed, regardless of its status. This can disrupt revenue streams and create operational chaos by forcing manual reprocessing of orders and generating unnecessary customer support inquiries. Organizations using affected versions of J2Store should prioritize immediate updates to mitigate this high-severity vulnerability.

CVE
CVE-2026-82189
Severity
HIGH
CVSS
8.7
EPSS
0.25%

Original NVD Description

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.