NONE · 0

CVE-2026-78065

Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away o...

Vulnerability Description

Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away only when the loaded address row had a **non-empty** `user_id` belonging to someone else. Guest-checkout address rows have an empty `user_id`, so that check never triggered for them — any logged-in account guessing a small, sequential `address_id` got a guest customer's full name, street address, and phone number rendered prefilled into the edit form.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-78065?

CVE-2026-78065 is a documented vulnerability. Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away o...

How severe is CVE-2026-78065?

CVSS scoring is not yet available for CVE-2026-78065. Check NVD for updates.

Is there a patch for CVE-2026-78065?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.