PT-2026-85014 · J2Store · J2Store
CVE-2026-78069
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
J2Store versions 1.0.0 through 3.3.21
J2Store versions 4.0.0 through 4.0.21
J2Store versions 4.1.0 through 4.1.6
Description
Missing authorization exists in the
J2StoreControllerApps delegation path via the appTask function, which instantiates app-plugin controllers without Access Control List (ACL) checks. Additionally, the applocalizationdata::getInstallerTool() function uses a caller-influenced table name without an allow-list. This allows an attacker to select a # j2store * table for truncation and construct a path to SQL files for execution, enabling a path-traversal-capable file read and execution.Recommendations
Update J2Store versions 1.0.0 through 3.3.21 to a version newer than 3.3.21.
Update J2Store versions 4.0.0 through 4.0.21 to a version newer than 4.0.21.
Update J2Store versions 4.1.0 through 4.1.6 to a version newer than 4.1.6.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
J2Store