PT-2026-85014 · J2Store · J2Store

CVE-2026-78069

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions J2Store versions 1.0.0 through 3.3.21 J2Store versions 4.0.0 through 4.0.21 J2Store versions 4.1.0 through 4.1.6
Description Missing authorization exists in the J2StoreControllerApps delegation path via the appTask function, which instantiates app-plugin controllers without Access Control List (ACL) checks. Additionally, the applocalizationdata::getInstallerTool() function uses a caller-influenced table name without an allow-list. This allows an attacker to select a # j2store * table for truncation and construct a path to SQL files for execution, enabling a path-traversal-capable file read and execution.
Recommendations Update J2Store versions 1.0.0 through 3.3.21 to a version newer than 3.3.21. Update J2Store versions 4.0.0 through 4.0.21 to a version newer than 4.0.21. Update J2Store versions 4.1.0 through 4.1.6 to a version newer than 4.1.6.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78069

Affected Products

J2Store