CVE-2026-7630 Details
Description
A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 45758e4ec22451ab944ae2ae826b1e70f6450dc9. It is recommended to apply a patch to fix this issue.
A vulnerability exists in InnoCommerce InnoShop versions through 0.7.8, specifically within the installation module's service provider. The issue arises because the installation routes are registered without checking if the application is already installed, leaving the endpoint '/install/complete' accessible without authentication or CSRF protection. This flaw allows an unauthenticated attacker to overwrite the '.env' file, erase the entire database using the 'migrate:fresh' command, and create a new administrator account, resulting in a complete system takeover.
Users are advised to update to the latest version of InnoShop, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 2, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/innocommerce/innoshop/ | [email protected] | ProductVendor |
| https://github.com/innocommerce/innoshop/commit/45758e4ec22451ab944ae2ae826b1e70f6450dc9 | [email protected] | Source CodeVendor |
| https://github.com/innocommerce/innoshop/issues/314 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/innocommerce/innoshop/issues/314#issuecomment-4357464458 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/806484 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360576 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360576/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| innocommerce InnoShop | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 2, 2026 | New CVE Received | [email protected] |
Volerion