Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash | |
| First Time appeared |
Aircheng-org
Aircheng-org iwebshop-5 |
|
| Weaknesses | CWE-326 CWE-916 |
|
| CPEs | cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aircheng-org
Aircheng-org iwebshop-5 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-08T18:19:56.188Z
Reserved: 2026-09-08T09:30:51.404Z
Link: CVE-2026-86670
No data.
Status : Deferred
Published: 2026-09-08T18:21:17.370
Modified: 2026-09-08T18:33:29.460
Link: CVE-2026-86670
No data.
OpenCVE Enrichment
No data.