CVE-2026-78065

Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non-owners away only when the loaded address row had a **non-empty** `user_id` belonging to someone else. Guest-checkout address rows have an empty `user_id`, so that check never triggered for them — any logged-in account guessing a small, sequential `address_id` got a guest customer's full name, street address, and phone number rendered prefilled into the edit form.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 13:06

Updated : 2026-09-03 17:30


NVD link : CVE-2026-78065

Mitre link : CVE-2026-78065

CVE.ORG link : CVE-2026-78065


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key