CVE-2026-82190
CVE-2026-82190 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1241.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.3)
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1241
- Published:
- Last modified:
Description
Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining guest access to that order's details and any purchased digital downloads. Because the token is never rotated, this exposure persists indefinitely even after the underlying secret-disclosure vector is patched, unless the Joomla secret itself is also rotated. The attack complexity (`AC:H`) is high because it depends on the secret already being known through a separate vector; it is not directly exploitable by an anonymous visitor with no other foothold.
Frequently asked questions
- What is CVE-2026-82190?
- Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining guest access to that order's details and any purchased digital downloads. Because the token is never rotated, this exposure persists indefinitely even after the underlying secret-disclosure vector is patched, unless the Joomla secret itself is also rotated. The attack complexity (`AC:H`) is high because it depends on the secret already being known through a separate vector; it is not directly exploitable by an anonymous visitor with no other foothold.
- How severe is CVE-2026-82190?
- CVE-2026-82190 has a CVSS 4.0 base score of 6.3, rated medium severity.
- Is CVE-2026-82190 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82190?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-82190 published?
- CVE-2026-82190 was published on 2026-09-15 and last updated on 2026-09-16.
References
Other CWE-1241 vulnerabilities
- CVE-2023-4695 — High (CVSS 8.1): Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- CVE-2026-73576 — Medium (CVSS 6.3): In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice…
- CVE-2026-6420 — Medium (CVSS 6.3): A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent…
- CVE-2026-82191 — Medium (CVSS 5.3): Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store…
- CVE-2025-13079 — Medium (CVSS 5.3): The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to…
- CVE-2025-32056 — Medium (CVSS 4.0): The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the…