CVE-2026-86670 Details
Description
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in aircheng iWebShop-5 versions through 5.15, specifically within the Authentication Storage component. The issue arises in the 'controllers/admin.php' file, where an unknown function improperly handles password hashing. This flaw allows for the creation of password hashes that require insufficient computational effort to crack. The vulnerability can be exploited remotely, although it is associated with a high level of complexity, making exploitation difficult.
Users are advised to update to a version of iWebShop that addresses this vulnerability. For those who have already been exposed to this vulnerability, it is recommended to change passwords and monitor for any unauthorized access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aircheng-org/iWebShop-5/ | [email protected] | ProductSource CodeVendor |
| https://github.com/aircheng-org/iWebShop-5/issues/7 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-86670 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908928 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399761 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399761/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | [email protected] |
| CWE-916 | Use of Password Hash With Insufficient Computational Effort | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aircheng-org iWebShop-5 | <= 5.15 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion