CVE-2026-86669

HIGH Status: Deferred

CVSS Scores

CVSS v3.x Base Score
7.3
HIGH
CVSS v2 Base Score
7.5
HIGH

Description

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Published
September 8, 2026 6:21 PM
Last Modified
September 8, 2026 7:20 PM
Source
[email protected]

Weaknesses (CWE)

CWE-287

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.