CVE-2026-86665 Details
Description
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in iWebShop-5 versions up to 5.15, specifically in the Update controller's index method within the update.php file. This vulnerability allows for unauthenticated database schema modifications by executing multiple ALTER TABLE statements. Additionally, the vulnerability clears the application's runtime cache directory. The issue can be exploited remotely, and a public exploit is available.
It is recommended to remove the public update controller from production environments or to require authentication plus a one-time upgrade token. Database schema changes should be managed through command-line installers rather than web-based interfaces.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aircheng-org/iWebShop-5/ | [email protected] | ProductVendor |
| https://github.com/aircheng-org/iWebShop-5/issues/2 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-86665 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908923 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399756 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399756/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aircheng-org iWebShop-5 | <= 5.15 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion