CVE-2026-86670
Deferred Deferred - Pending Action

Password Hash Weakness in iWebShop

Vulnerability report for CVE-2026-86670, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: VulDB

Description

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aircheng-org iwebshop to 5.15 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-326 The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in aircheng-org iWebShop-5 up to version 5.15, specifically in the authentication storage component. An attacker can manipulate the Password argument in the admin.php file to force a weak password hash. This makes it easier to crack passwords through brute force or other methods. The attack requires high complexity and is difficult to exploit but has been published, increasing risk.

Impact Analysis

If exploited, this flaw could allow unauthorized access to admin accounts by cracking weak password hashes. Attackers might gain control over the e-commerce system, steal sensitive data, or manipulate transactions. Since the exploit is public, the risk of misuse is higher, especially if the software is not updated.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR (data protection) and HIPAA (health information privacy). Non-compliance risks fines, legal action, and reputational damage. Organizations using this software must address it promptly to maintain regulatory compliance.

Mitigation Strategies

Immediately update iWebShop to the latest version if available. If no update exists, consider disabling the affected component or restricting access to the admin.php file. Monitor network traffic for unusual authentication attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86670. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart